platform-api
Authentication
Overview
OrbioCloud provides tenant-scoped user authentication. Each user belongs to exactly one tenant — email uniqueness is enforced per-tenant, so [email protected] in Tenant A is a completely different user from [email protected] in Tenant B.
Sign Up
const { user, session } = await orbio.auth.signUp({
email: '[email protected]',
password: 'minimum8chars',
metadata: { display_name: 'Alice' }, // optional
});
// session.access_token is stored in memory automaticallyREST equivalent:
curl -X POST https://api.orbiocloud.com/api/v1/auth/signup \
-H 'X-API-Key: your_publishable_key' \
-H 'Content-Type: application/json' \
-d '{"email": "[email protected]", "password": "minimum8chars"}'Sign In
const { user, session } = await orbio.auth.signIn({
email: '[email protected]',
password: 'minimum8chars',
});
// Returns user profile + session tokensSign Out
await orbio.auth.signOut();
// Session cleared from memory even if server call failsGet Current User
const user = await orbio.auth.getUser();
// Returns: { id, email, created_at, user_metadata }Refresh Session
const session = await orbio.auth.refreshSession();
// Returns new access_token + refresh_tokenPassword Reset
await orbio.auth.resetPassword('[email protected]');
// Sends reset email. Always returns success (prevents user enumeration).Email Verification
const result = await orbio.auth.verify(token, 'signup');
// Types: 'signup', 'email', 'recovery', 'invite'Auth State Changes
const unsubscribe = orbio.auth.onAuthStateChange((event, session) => {
console.log(event); // 'SIGNED_IN' | 'SIGNED_OUT' | 'TOKEN_REFRESHED'
});
// Later: unsubscribe();Headers
The SDK handles headers automatically. For direct REST calls:
X-API-Key — Your platform API key (required on every request)
X-Access-Token — User access token (for authenticated endpoints like /me, /signout)
Important: User tokens go in X-Access-Token, NOT the Authorization header. The Authorization header is reserved for legacy module API keys.