Authentication and authorization in ProductFlo
Authorization
header using the Bearer scheme:
sub
: The user’s unique identifierexp
: Expiration timeiat
: Issued at timetenant_id
: The current tenant context (optional)role
: The user’s rolepermissions
: The user’s permissions (optional)Login
Token Issuance
API Access
Token Expiration
Token Refresh
credentials: 'include'
in your fetch requests to ensure cookies are sent.Enable 2FA
Initial Login
2FA Challenge
Submit 2FA Code
Complete Authentication