Authentication
Trade organization, email, and password for a token — or use an API key for server-to-server feeds. Part of the documentation.
POST/auth/login
Signs in with organization, email, and password, and returns a bearer token valid for 12 hours. A missing organization means the default organization. One shared 401 covers unknown organization, unknown email, and wrong password, so the endpoint reveals neither which organizations nor which addresses exist.
curl -X POST https://filodos.gr/filodos-dashboard/api/scoring/auth/login \
-H 'Content-Type: application/json' \
-d '{"organization": "acme", "email": "feed@acme.example", "password": "…"}'
{"access_token": "eyJhbGciOi…", "token_type": "bearer"}
| Field | Required | Notes |
|---|---|---|
organization | No | Your organization slug, lowercase. Blank means the default organization. The name filodos reaches the default organization (the slug avlo) when no other organization has that slug. |
email | Yes | Matched case-insensitively inside your organization. |
password | Yes | Store it in a vault, never in code. |
GET/auth/me
Returns who the credential belongs to: id, email, role, organization, and — for driver logins — the visible vehicle ids. Use it after sign-in to confirm the role and the organization before you read further.
curl https://filodos.gr/filodos-dashboard/api/scoring/auth/me \
-H "Authorization: Bearer eyJhbGciOi…"
Use the credential
Send the token or key on every other call:
Authorization: Bearer <access_token or filodos_… key>
A 401 means the credential is missing, expired, revoked, or deleted — sign in again or replace the key. Long-running feeds should use an API key instead of re-signing-in every 12 hours. Never put the credential in the URL: URLs land in access logs.
Keys that start with avlo_ do not work from 2026-10-11. All keys start with filodos_.