Skip to main content

Authentication API

Endpoints for user authentication and token management.

Personal API access token

The simplest way to call the API as yourself is with your personal access token. Sign in to IceHrm, open Personal Details → API Access, and you'll find both values you need:

  • API Base URL — the address every request goes to. On a self-hosted install this is your site URL followed by api/; on IceHrm Cloud it is your site URL with /app/ replaced by /api/.
  • API Access Token — send it in the Authorization header of each request:
Authorization: Bearer <your-api-access-token>

If a token is ever exposed, click Reset Token on the same tab. This issues a new token and immediately stops the old one from working, so update any integration that relied on it.

Enabling API access

The API Access tab only shows a token when an administrator has enabled the REST API (System → Settings → API).

Get OAuth Access Token

Authenticates a user and returns an access token for subsequent API calls. This endpoint does not require an existing token.

POST /oauth/token

Request Body:

{
"grant_type": "password",
"client_id": "your-client-id",
"client_secret": "your-client-secret",
"username": "[email protected]",
"password": "user-password"
}

Required Fields:

  • grant_type: Must be password
  • client_id: OAuth client identifier
  • client_secret: OAuth client secret
  • username: User's login email
  • password: User's password

Response: 200 OK

{
"access_token": "eyJhbGciOiJIUzI1NiIs...",
"token_type": "Bearer",
"expires_in": 3600
}

Error Response: 401 Unauthorized if credentials are invalid.

Update User Password

Updates the password for the currently authenticated user.

POST /user/password

Request Body:

{
"current_password": "old-password",
"new_password": "new-secure-password"
}

Response: 200 OK