API

Authentication

JWT Bearer tokens for Public API v1.

Public API v1 uses JWT Bearer tokens for approved server-side integrations.

Authorization: Bearer {accessToken}
Content-Type: application/json

Login

POST https://pro.curiotime.com/api/v1/auth/login
{
  "email": "integration@company.example",
  "password": "…"
}

Response:

{
  "success": true,
  "data": {
    "accessToken": "eyJ…",
    "refreshToken": "…",
    "accessTokenExpiresAtUtc": "2026-08-25T11:00:00Z",
    "refreshTokenExpiresAtUtc": "2026-09-24T10:00:00Z"
  },
  "errors": null
}

Refresh

POST https://pro.curiotime.com/api/v1/auth/refresh
{
  "refreshToken": "…"
}
Integration Role
Payroll / accounting (read hours) owner or accountant
Roster read owner, accountant, or manager
Partner clock in / out owner or manager
Employee-only token employee — own data only; not for payroll

Health check (no auth)

GET https://pro.curiotime.com/api/v1/health

Use for uptime monitoring only.

Security practices

  • Never store passwords or refresh tokens in client-side web apps or git
  • Use HTTPS only
  • Revoke compromised sessions: POST https://pro.curiotime.com/api/v1/auth/revoke
  • Use a dedicated service account — not a personal employee login
  • Keep login and refresh-token handling on your server; never put integration credentials in browser or mobile code
  • The companyId in a punch route must match the company in the token