Skip to content

Authentication ​

Use API tokens for integrations and Galileo. The web console uses HTTP-only session cookies.

API token ​

  1. Sign in at Hashiro.
  2. Open My Account.
  3. Generate an API key and copy it immediately.
  4. Store it as a private environment variable or secret.

The token is shown only once. Generating a new token invalidates the old one. Tokens inherit the user's permissions and organization scope.

bash
curl --fail-with-body \
  -H "X-HASHIRO-TOKEN: $HASHIRO_TOKEN" \
  https://api.hashiro.ai/api/organizations/me

Both providers and clients use this header and the same production base URL. Galileo reads the token from api_key in its configuration.

POST /users/generateToken generates a replacement token for the authenticated user. This rotates a credential, so use the UI for initial setup and avoid calling it as a connectivity test.

Browser sessions ​

POST /auth/signin accepts:

json
{
  "email": "[email protected]",
  "password": "your-password"
}

The response can require MFA or a first-login password change before full access. Session cookies are access_token and refresh_token. The refresh cookie renews an expired access token. GET /auth/logout clears the session.

MFA ​

MethodPathPurpose
GET/auth/otp/createStart TOTP setup in an authenticated setup session
POST/auth/otp/createVerify setup and enable MFA
POST/auth/otp/validateComplete MFA during login
POST/users/otp/enableStart authenticated MFA setup
POST/users/otp/resetReset own MFA where allowed
POST/users/otp/disableDisable own MFA where policy allows

Use the console for the full setup flow. OTP verification is rate-limited, and organization policy can require MFA.

Password recovery and change ​

MethodPathBody
POST/auth/password-reset/request{"email":"[email protected]"}
POST/auth/password-reset/confirm{"token":"RESET_TOKEN","password":"NEW_PASSWORD"}
POST/users/me/change-password{"currentPassword":"CURRENT_PASSWORD","newPassword":"NEW_PASSWORD"}

Recovery uses the emailed token. Provisioned users may need to change their password before accessing the console.

Invitation acceptance ​

POST /auth/register accepts an invitation token and the required registration fields. This activates an invited account; it is not a general-purpose unauthenticated organization-creation endpoint.

Common failures ​

An invalid token returns an authentication failure. A valid token can still receive 403 for an unauthorized organization or operation. Regenerate a leaked token and update integrations that used it.

Hashiro. Continuous Threat Exposure Management.