Login & Logout API
Username and API key also acts like your key to the APIs. You need to have an access token for making any further API calls, which you can receive by logging in manually or programmatically using these credentials.
Signzy APIs adhere to authentication defined by Swagger 2.0 specifications. Each call to the APIs should include an 'Authorization' header or 'access_token' query parameter for authentication.
Logging In
Logging in into the API services requires a simple HTTP call with authentication password. Following section mentions data to be input, expected output and meaning of fields.
curl --location --request POST 'https://contracting-preproduction.signzy.tech/api/customers/login' \
--data-raw '{
"username": "enter your valid username",
"password": "enter your valid password"
}'Sending Authenticated Requests
Once you have an access token from the login API call, you can send further calls to different endpoints by passing the access-token in Authorization header or in access_token query (GET) parameter.
It is advisable to send Access Token in header since, query parameters are sometimes saved in the log files thereby exposing vulnerabilities until the access_token is deleted from sessions.
Security
Anybody with your API key/password or an Access Token generated using them can access all information you have created and also send requests on behalf of you.. It is strongly recommended to not send API-key/Password to client side and instead use reverse proxy to call Signzy APIs.
In case you think an access token is compromised, you should delete it using logout. Please inform us if your Signzy Password/API-key is compromised as soon as possible, so that we can disable & create new ones and prevent any misuse of your data.
Logging Out
To logout you simply need to call the logout route with the access token in 'access_token' query parameter or as 'Authorization' header.
https://contracting-preproduction.signzy.tech/api/customers/logout?access_token=...accessToken...
Response is 204 status code with no content, indicating the Access-token has been deleted.