Authentication
Smart KYC currently supports product-user bearer tokens for authenticated product routes. Internal staff authentication is a separate boundary and must never be used for customer integrations.
Current sandbox authentication
Call POST /api/v1/auth/login with a product-user email and password. The response returns productAuthToken and productAuthTokenExpiresAt.
curl --request POST \
"$SMART_KYC_BASE_URL/api/v1/auth/login" \
--header "Content-Type: application/json" \
--data '{
"email": "owner@example.com",
"password": "your-password"
}'Send the token on product API requests:
Authorization: Bearer <productAuthToken>
Store the expiry and obtain a fresh token through the supported product authentication flow. Never place the token in URLs, logs, analytics attributes, or customer-visible error messages.
Customer API keys
The dashboard can create, rotate, revoke, and list customer API keys. A raw key is returned only once during creation or rotation.
However, the current NestJS product guard does not validate the raw customer API key as request authentication. Until that backend integration exists:
- do not advertise API-key authentication as production-ready;
- do not ask customers to send
X-Customer-Api-Key-Idmanually; - do not treat the display prefix as a credential;
- do not build server integrations around a product user’s password.
Environments
Use an environment variable for the API origin:
SMART_KYC_BASE_URL
The final documentation will publish explicit sandbox and production origins after the backend public OpenAPI document defines its servers entries.
Internal authentication is separate
Routes under /api/v1/internal/* use internal staff bearer tokens and resolved internal roles. Those endpoints and credentials are not part of the customer API and will be excluded from the public OpenAPI reference.