Skip to main content

API Authentication

SDD Classification: L3-Technical Authority: Engineering Team Review Cycle: Quarterly
This document details the authentication and authorization implementation in Materi’s API Service, including JWT validation, permission checking, and integration with Shield authentication service.

Authentication Flow


JWT Token Structure

Access Token Claims

Token Lifetimes


Authentication Middleware

Implementation

Cache Operations


Authorization

Permission Levels

Permission Hierarchy

Permission Service


Token Refresh

Refresh Flow

Implementation


API Key Authentication

API Key Format

API Key Middleware


Rate Limiting by Auth

Rate Limit Tiers

Endpoint-Specific Limits

Rate Limiter Implementation


Security Headers

Response Headers

CORS Configuration


Token Blacklisting

Blacklist Operations



Document Status: Complete Version: 2.0