Authentication
Use API tokens for integrations and Galileo. The web console uses HTTP-only session cookies.
API token
- Sign in at Hashiro.
- Open My Account.
- Generate an API key and copy it immediately.
- Store it as a private environment variable or secret.
The token is shown only once. Generating a new token invalidates the old one. Tokens inherit the user's permissions and organization scope.
curl --fail-with-body \
-H "X-HASHIRO-TOKEN: $HASHIRO_TOKEN" \
https://api.hashiro.ai/api/organizations/meBoth providers and clients use this header and the same production base URL. Galileo reads the token from api_key in its configuration.
POST /users/generateToken generates a replacement token for the authenticated user. This rotates a credential, so use the UI for initial setup and avoid calling it as a connectivity test.
Browser sessions
POST /auth/signin accepts:
{
"email": "[email protected]",
"password": "your-password"
}The response can require MFA or a first-login password change before full access. Session cookies are access_token and refresh_token. The refresh cookie renews an expired access token. GET /auth/logout clears the session.
MFA
| Method | Path | Purpose |
|---|---|---|
| GET | /auth/otp/create | Start TOTP setup in an authenticated setup session |
| POST | /auth/otp/create | Verify setup and enable MFA |
| POST | /auth/otp/validate | Complete MFA during login |
| POST | /users/otp/enable | Start authenticated MFA setup |
| POST | /users/otp/reset | Reset own MFA where allowed |
| POST | /users/otp/disable | Disable own MFA where policy allows |
Use the console for the full setup flow. OTP verification is rate-limited, and organization policy can require MFA.
Password recovery and change
| Method | Path | Body |
|---|---|---|
| POST | /auth/password-reset/request | {"email":"[email protected]"} |
| POST | /auth/password-reset/confirm | {"token":"RESET_TOKEN","password":"NEW_PASSWORD"} |
| POST | /users/me/change-password | {"currentPassword":"CURRENT_PASSWORD","newPassword":"NEW_PASSWORD"} |
Recovery uses the emailed token. Provisioned users may need to change their password before accessing the console.
Invitation acceptance
POST /auth/register accepts an invitation token and the required registration fields. This activates an invited account; it is not a general-purpose unauthenticated organization-creation endpoint.
Common failures
An invalid token returns an authentication failure. A valid token can still receive 403 for an unauthorized organization or operation. Regenerate a leaked token and update integrations that used it.