Developers
Authentication
OpenID Connect through Karibu ID’s identity service (Keycloak), bearer access tokens, and a passkey for sensitive actions. There are no API keys.
People: OpenID Connect
People sign in to Karibu ID’s identity service (Keycloak) with OpenID Connect, with a passkey or a second factor. Your organisation’s own identity provider can be connected for single sign-on (OIDC or SAML), with your groups mapped to reader roles; an unmapped group grants nothing.
Each call carries the access token as Authorization: Bearer <token>. Tokens live for a few minutes; refresh them through the identity service, never by storing a password.
Sensitive actions: a recent passkey
Some actions (sharing, publishing, changing members, single sign-on settings) need a passkey sign-in within the last five minutes. Without one, Core answers 401 insufficient_user_authentication (RFC 9470); sign in again with the passkey and repeat the call.
Platforms: client credentials with private_key_jwt
A Connect platform’s confidential client authenticates with client credentials and private_key_jwt: a short-lived JWT signed with one of the public keys your reader admin registered (POST /v1/connect/keys; RSA, EC or Ed25519, always with a kid, up to five at once so you can rotate).
With dpop_bound: true the token is bound to your key (RFC 9449): send Authorization: DPoP <token> and a fresh DPoP proof with every request. A suspended platform’s tokens stop working at its next request.
Operations: The signed-in person
14 operations
| Method | Path | Operation |
|---|---|---|
| GET | /v1/me | Me |
| POST | /v1/me/devices/push-tokens | Add Push Token |
| DELETE | /v1/me/devices/push-tokens/{token_id} | Remove Push Token |
| GET | /v1/me/features | Features |
| GET | /v1/me/inbox | Inbox |
| POST | /v1/me/inbox/{item_id}/read | Read One |
| POST | /v1/me/inbox/read-all | Read All |
| GET | /v1/me/inbox/unread-count | Unread Count |
| GET | /v1/me/jobs/{job_id} | Job |
| GET | /v1/me/notification-preferences | Get Preferences |
| PUT | /v1/me/notification-preferences | Put Preferences |
| GET | /v1/me/organisations | Organisations |
| GET | /v1/me/terms | My Terms |
| POST | /v1/me/terms/{kind}/accept | Accept Terms |