Depa LogoDocsv1
API Reference

Authentication

Exchange your Depa user credentials for a JSON Web Token and send it on every request.

  1. Call POST /sign_in with your email and password. If the user has two-factor authentication enabled, add the current one-time code as otp_attempt.
  2. Send the returned token in the Authorization header of every other request: Authorization: Bearer <token>.
  3. Tokens expire. An expired or missing token returns 401 with {"error": "You are not authenticated."}; sign in again to get a new one.

The token is a standard JWT, so you can read its payload without calling the API. It includes user_uuid, main_account_uuid, your roles, the vaults you can access (use these IDs in the /vaults/{vault_id}/… endpoints) and exp, the expiry time in Unix seconds.

Sandbox and production are separate environments with separate credentials. Build and test against https://sandbox.depasify.com/api/v1.

Sign in

POST/sign_in

Exchanges a user's email and password for a JWT. Send it as Authorization: Bearer <token> on every other request. This is the only endpoint that doesn't need a token.

If the user has two-factor authentication enabled, include the current code from their authenticator app in otp_attempt. After too many failed attempts the user is locked and sign-in returns 423; contact Depa support to unlock it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Credentials of a Depa user.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/sign_in" \  -H "Content-Type: application/json" \  -d '{    "email": "developer@yourcompany.com",    "password": "your-password"  }'
{  "data": {    "token": "eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyX3V1aWQiOiI3ZGU4OWQ2MiIsImV4cCI6MTc3NTQ4Nzk1M30.Qm9ndXNTaWduYXR1cmU"  }}
🍪 We do not track your behaviour or use any cookie on this site.