Filodos

Authentication

Trade organization, email, and password for a token — or use an API key for server-to-server feeds. Part of the documentation.

POST/auth/login

Signs in with organization, email, and password, and returns a bearer token valid for 12 hours. A missing organization means the default organization. One shared 401 covers unknown organization, unknown email, and wrong password, so the endpoint reveals neither which organizations nor which addresses exist.

curl -X POST https://filodos.gr/filodos-dashboard/api/scoring/auth/login \
  -H 'Content-Type: application/json' \
  -d '{"organization": "acme", "email": "feed@acme.example", "password": "…"}'

{"access_token": "eyJhbGciOi…", "token_type": "bearer"}
FieldRequiredNotes
organizationNoYour organization slug, lowercase. Blank means the default organization. The name filodos reaches the default organization (the slug avlo) when no other organization has that slug.
emailYesMatched case-insensitively inside your organization.
passwordYesStore it in a vault, never in code.

GET/auth/me

Returns who the credential belongs to: id, email, role, organization, and — for driver logins — the visible vehicle ids. Use it after sign-in to confirm the role and the organization before you read further.

curl https://filodos.gr/filodos-dashboard/api/scoring/auth/me \
  -H "Authorization: Bearer eyJhbGciOi…"

Use the credential

Send the token or key on every other call:

Authorization: Bearer <access_token or filodos_… key>

A 401 means the credential is missing, expired, revoked, or deleted — sign in again or replace the key. Long-running feeds should use an API key instead of re-signing-in every 12 hours. Never put the credential in the URL: URLs land in access logs.

Keys that start with avlo_ do not work from 2026-10-11. All keys start with filodos_.