Authentication
JWT Bearer tokens for Public API v1.
Public API v1 uses JWT Bearer tokens for approved server-side integrations.
Authorization: Bearer {accessToken}
Content-Type: application/json
Login
POST https://pro.curiotime.com/api/v1/auth/login
{
"email": "integration@company.example",
"password": "…"
}
Response:
{
"success": true,
"data": {
"accessToken": "eyJ…",
"refreshToken": "…",
"accessTokenExpiresAtUtc": "2026-08-25T11:00:00Z",
"refreshTokenExpiresAtUtc": "2026-09-24T10:00:00Z"
},
"errors": null
}
Refresh
POST https://pro.curiotime.com/api/v1/auth/refresh
{
"refreshToken": "…"
}
Recommended roles
| Integration | Role |
|---|---|
| Payroll / accounting (read hours) | owner or accountant |
| Roster read | owner, accountant, or manager |
| Partner clock in / out | owner or manager |
| Employee-only token | employee — own data only; not for payroll |
Health check (no auth)
GET https://pro.curiotime.com/api/v1/health
Use for uptime monitoring only.
Security practices
- Never store passwords or refresh tokens in client-side web apps or git
- Use HTTPS only
- Revoke compromised sessions:
POST https://pro.curiotime.com/api/v1/auth/revoke - Use a dedicated service account — not a personal employee login
- Keep login and refresh-token handling on your server; never put integration credentials in browser or mobile code
- The
companyIdin a punch route must match the company in the token