Authentication
After completing login or register, the client stores token credentials and makes API requests using an access token.
Tokens
Section titled “Tokens”| Token | Purpose |
|---|---|
access_token | Short-lived; passed in Authorization: Bearer <access_token> header |
refresh_token | Obtains new access tokens without re-entering credentials |
Web client flow upon 401 on a protected route:
POST /api/v1/auth/refreshwith refresh token.- Success ➔ Save new access token (and refresh token if rotated).
- Failure ➔ Log out, redirect to sign in.
Never store tokens in URLs, application server logs, or public code repositories.
Endpoints Overview
Section titled “Endpoints Overview”| Method & Route | Description |
|---|---|
POST /api/v1/auth/register | Sign up (email, name, password) |
POST /api/v1/auth/login | Sign in |
POST /api/v1/auth/refresh | Refresh access token |
POST /api/v1/auth/forgot-password | Request password reset token |
POST /api/v1/auth/reset-password | Set new password using reset token |
| OAuth | Google / Yandex / VK / Mail (if enabled on server) |
Password reset form: app.planovik.pro/forgot-password.
Sign up page: app.planovik.pro/register.
Rate Limiting
Section titled “Rate Limiting”The Auth routes are protected by dedicated rate limiters against brute-force login/register attempts. Upon receiving 429, back off and wait before retrying.
Personal API Keys
Section titled “Personal API Keys”For developer integrations (distinct from user session JWTs and AI BYOK keys):
- Created in Account Settings ➔ API.
- Full secret key is displayed once.
- Key count limits apply (up to 10 in UI).
- Revoking a key immediately disables all requests using it.
Key scopes are detailed in External API Documentation. Pass keys in Authorization: Bearer plk_... headers and never commit them to code repositories.
Related Sections
Section titled “Related Sections”- External API
- Quick Start — user registration overview
- AI Assistant — provider BYOK keys