Aspec API

Welcome to the Aspec API. Use the guidance below to authenticate, explore the endpoints and find related documentation.

1. Authentication

The API uses JWT bearer tokens. Request a token by posting the e-mail address and password of an Aspec user that is active and allowed to use the API to POST /auth/login:

POST /auth/login
Content-Type: application/json

{
  "email": "user@example.com",
  "password": "your-password"
}

A successful call returns the token and its expiration moment (UTC):

{
  "token": "<jwt-access-token>",
  "expiresAtUtc": "2025-01-01T12:15:00Z"
}

Send that token on every subsequent request:

Authorization: Bearer <jwt-access-token>

Tokens have a sliding expiration. Every successful authenticated request returns a freshly issued token in the response headers:

X-Refreshed-Token: <new-jwt-access-token>
X-Refreshed-Token-Expires-At: 2025-01-01T12:30:00.0000000Z

Replace your stored token with the value of X-Refreshed-Token after each call. As long as you keep calling the API within the token lifetime, you never have to log in again. Only after a period of inactivity does the token expire and do you need to call /auth/login once more.

Invalid credentials, an inactive account or an account without API permission all return 401 Unauthorized. Access revoked in Aspec takes effect immediately, also for tokens that have not expired yet. Contact the Aspec team to have API access enabled for your user.

2. API documentation (OpenAPI)

The full API surface is described by an OpenAPI document. Explore and test the endpoints interactively with the Scalar API reference:

Open interactive API reference View raw OpenAPI document

The raw specification lives at /openapi/v1.json and can also be imported into tools such as Postman or Insomnia.

3. Business process documentation

Additional documentation describing the business processes supported by this API will be listed here as it becomes available.