Skip to content

Authentication

After completing login or register, the client stores token credentials and makes API requests using an access token.

TokenPurpose
access_tokenShort-lived; passed in Authorization: Bearer <access_token> header
refresh_tokenObtains new access tokens without re-entering credentials

Web client flow upon 401 on a protected route:

  1. POST /api/v1/auth/refresh with refresh token.
  2. Success ➔ Save new access token (and refresh token if rotated).
  3. Failure ➔ Log out, redirect to sign in.

Never store tokens in URLs, application server logs, or public code repositories.

Method & RouteDescription
POST /api/v1/auth/registerSign up (email, name, password)
POST /api/v1/auth/loginSign in
POST /api/v1/auth/refreshRefresh access token
POST /api/v1/auth/forgot-passwordRequest password reset token
POST /api/v1/auth/reset-passwordSet new password using reset token
OAuthGoogle / Yandex / VK / Mail (if enabled on server)

Password reset form: app.planovik.pro/forgot-password.
Sign up page: app.planovik.pro/register.

The Auth routes are protected by dedicated rate limiters against brute-force login/register attempts. Upon receiving 429, back off and wait before retrying.

For developer integrations (distinct from user session JWTs and AI BYOK keys):

  • Created in Account Settings ➔ API.
  • Full secret key is displayed once.
  • Key count limits apply (up to 10 in UI).
  • Revoking a key immediately disables all requests using it.

Key scopes are detailed in External API Documentation. Pass keys in Authorization: Bearer plk_... headers and never commit them to code repositories.