Dokümantasyon

Auth

Son-kullanıcı kimlik doğrulama. API key kullanıcı oturumu değildir — projeyi seçer.

Kurallar

Her istek: {EDGE}/auth/… + X-Liap-Key. Proje UUID ve JSON project_id yok.

API key projeyi seçer. Kullanıcı oturumu değildir.

Kayıt/giriş: yalnız X-Liap-Key. /auth/me, MFA, passkey: X-Liap-Key + Authorization: Bearer lca_…

Yanıt: access_token (lca_…), refresh_token (lcr_…), expires_in (900), user — aynı alanlar tokens altında da gelir.

user.id UUID. user.user_metadata (alias: metadata) kullanıcı JSON'u; user.app_metadata yalnız service-role.

Kayıt sonrası public.profiles satırı aynı UUID ile açılır. Ek kolonlar GET/PUT /auth/user-fields ile tanımlanır.

401 → POST /auth/refresh (rotation). Refresh gövdesinde refresh_token; header’da yine X-Liap-Key.

MethodPathAçıklama
POST/auth/registerKayıt (+ user_metadata)
POST/auth/loginGiriş
GET/auth/meMevcut kullanıcı (Key + Bearer lca_)
PATCH/auth/mename + user_metadata (kalıcı)
POST/auth/refreshToken yenile
POST/auth/logoutÇıkış
POST/auth/anonymousAnonim
GET/auth/usersAdmin liste (dashboard oturumu)
PATCH/auth/users/{id}Admin: role, user_metadata, app_metadata, email_verified
GET/auth/user-fieldsEk alan şeması (profiles kolonları)
PUT/auth/user-fieldsEk alan şeması yaz + ALTER profiles
GET/auth/rolesProje rol listesi
PUT/auth/rolesRolleri kaydet (müşteri tanımlı)
POST/auth/recoverŞifre sıfırlama

Kayıt / giriş + metadata

Node.js
const session = await fetch(`${EDGE}/auth/register`, {
  method: 'POST',
  headers: { 'Content-Type': 'application/json', 'X-Liap-Key': API_KEY },
  body: JSON.stringify({
    email: '[email protected]',
    password: 'min8chars',
    name: 'Ayse',
    user_metadata: { username: 'ayse', phone: '+90555' },
  }),
}).then(r => r.json())

// session.user.id — UUID
// session.user.user_metadata / metadata — aynı JSON
// session.user.app_metadata — {}
// profiles satırı aynı id ile oluşur

const { access_token, refresh_token } = session

const me = await fetch(`${EDGE}/auth/me`, {
  headers: { Authorization: `Bearer ${access_token}`, 'X-Liap-Key': API_KEY },
}).then(r => r.json())

await fetch(`${EDGE}/auth/me`, {
  method: 'PATCH',
  headers: {
    Authorization: `Bearer ${access_token}`,
    'X-Liap-Key': API_KEY,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({ user_metadata: { username: 'ayse2' } }),
})

const profiles = await fetch(
  `${EDGE}/db/tables/profiles/rows?filter=id.eq.${session.user.id}`,
  { headers: { 'X-Liap-Key': API_KEY } },
).then(r => r.json())

Ek alan şeması (profiles)

PUT /auth/user-fields { fields: [{ name, type, required, in_signup }] } — type: text | bool | int8 | timestamptz | float8.

Şema _liap_meta.auth_user_fields içinde saklanır; profiles tablosuna kolon eklenir. PK = auth user id.

Node.js
// Dashboard / service-role
await fetch(`${EDGE}/auth/user-fields`, {
  method: 'PUT',
  headers: { 'Content-Type': 'application/json', 'X-Liap-Key': API_KEY },
  body: JSON.stringify({
    fields: [
      { name: 'username', type: 'text', required: true, in_signup: true },
      { name: 'phone', type: 'text', required: false, in_signup: true },
    ],
  }),
})

Refresh

Node.js
const next = await fetch(`${EDGE}/auth/refresh`, {
  method: 'POST',
  headers: { 'Content-Type': 'application/json', 'X-Liap-Key': API_KEY },
  body: JSON.stringify({ refresh_token }),
}).then(r => r.json())
const access_token = next.access_token

MFA / OAuth / Passkey

MethodPathAçıklama
POST/auth/mfa/setupTOTP kurulum
POST/auth/mfa/verifyMFA doğrula
GET/auth/oauth/google/start?redirect_uri=OAuth başlat
POST/auth/passkey/register/beginPasskey begin
Node.js
import { createClient } from '@liap-cloud/sdk'
const liap = createClient(EDGE, { apiKey: API_KEY })
await liap.auth.register({ email: '[email protected]', password: 'sifre12345' })
// await liap.auth.passkey.register()
// await liap.auth.mfa.setup()

Docs · API