Authentication
Every endpoint in this guide requires a credential sent in the Authorization header.
Getting a token
API tokens are issued by an AnchorPoint superadmin from the admin application (or by an operator running api:token generate on the server). Ask your AnchorPoint administrator for one, giving them:
- a name identifying your integration (e.g.
marketing-site-production), and - whether the token should expire, and when.
The token is a 64-character random string.
The token is shown only at the moment it is created or rotated — only a SHA-256 hash is stored, so nobody (including AnchorPoint support) can recover it later. If you lose it, ask for a rotation.
Sending a token
Send the token as a bearer credential on every request:
Authorization: Bearer 0k3NrQ9xVb2LpYd7...
JavaScript
const res = await fetch(`${API_BASE}/v2/public/courses`, {
headers: { Authorization: `Bearer ${process.env.ANCHORPOINT_API_TOKEN}` },
});
const { data } = await res.json();
PHP (Laravel)
$response = Http::withToken(config('services.anchorpoint.token'))
->get(config('services.anchorpoint.base_url') . '/v2/public/courses');
Python
requests.get(
f"{API_BASE}/v2/public/courses",
headers={"Authorization": f"Bearer {os.environ['ANCHORPOINT_API_TOKEN']}"},
timeout=10,
)
The token must be stored server-side — in an environment variable or secret manager — and never shipped to a browser, a mobile bundle, or a public repository. A token is not scoped to a user; anyone holding it can read your public catalogue.
API token or JWT
Every endpoint in this guide sits behind the api.or.jwt middleware, which accepts either credential in the same header:
| Credential | Issued to | Typical caller |
|---|---|---|
| API token | An integration | Marketing site, partner system |
| JWT | A signed-in AnchorPoint user | The student/admin web app |
This means your integration and the logged-in student app can share one set of endpoints. The only behavioural difference is personalisation: a JWT identifies a user, so GET /public/class/{id} can report that user's own registration. An API token has no user behind it, so those fields always come back empty — see Get a class.
Token lifecycle
| Event | Effect on your requests |
|---|---|
Token expires (expires_at passes) | 401 on every request, immediately |
| Token revoked by an admin | 401 on every request, immediately |
| Token rotated | The old secret stops working the moment the new one is issued |
| Token deleted | 401, and the token's name cannot be reused |
Successful requests stamp a last_used_at timestamp on the token (throttled to one write per minute), which administrators use to spot dormant integrations.
Plan for a rotation window: if your platform supports it, read the token from configuration at request time rather than at boot, so a rotation does not require a redeploy. See Handling a rotated token without downtime.