Skip to main content
The AfterCare API uses JSON Web Tokens (JWT) for authentication. When you register or log in, the API issues two tokens: a short-lived access token you attach to every protected request, and a longer-lived refresh token you use to obtain a new access token when the current one expires. No API keys or cookies are involved — all authentication state lives in these two tokens.
Pass your access token in the Authorization header on every protected request:
The /auth/* routes, GET /health, and GET /drive/callback are public and do not require this header.

Auth Flow

Logging Out

Call POST /auth/logout to revoke the current session. Pass your refresh token in the request body so the API can identify the session to revoke. This endpoint is idempotent — it always returns 204 No Content regardless of whether the token was already revoked or the session never existed.
string
The refresh token for the session you want to end. If omitted, the endpoint still returns 204 without taking any action.
After logout, discard both the access token and the refresh token from your client. Any subsequent request using the old access token continues to be accepted until its 15-minute window closes, so log out promptly when a session ends.
Build a lightweight token manager in your client that tracks the access token expiry (accessExpiresInSeconds) and calls /auth/refresh automatically before it lapses. This keeps your users seamlessly authenticated without forcing repeated logins.

Token Lifetimes at a Glance