Developers

Authentication

The Member API authenticates every request with a Firebase ID token. Members sign in with your corporate's Firebase tenant; you pass their ID token straight to the API.

How it works

The Member API is authenticated end-to-end with Firebase Authentication. There are no API keys and no token-exchange step: a member signs in on the client with your corporate's Firebase tenant (email/password, Google, or Apple Sign-In), and you send the resulting Firebase ID token directly to /public-api/v2/member/*. Hapana verifies the token's signature against Google's public keys, resolves the member from its uid, and scopes the request to the site you name.

Making an authenticated call

Pass the Firebase ID token as a bearer token and identify the site with the X-Site-ID header:

curl https://api.hapana-app.com/public-api/v2/member/profile \
  -H "Authorization: Bearer <firebase-id-token>" \
  -H "X-Site-ID: <site-id>"

Every /public-api/v2/member/* endpoint uses this same pair of headers. The token identifies who the member is; X-Site-ID identifies which of your sites the call is scoped to.

No login or logout endpoints. Sign-in, sign-out, and password resets are handled entirely by the Firebase SDK on the client. The Member API never sees a password — only the short-lived ID token Firebase issues after a successful sign-in.

Token lifetime & refresh

Firebase ID tokens expire after one hour. The Firebase SDK refreshes them transparently, but if you cache a token yourself, force a fresh one before it expires:

// Firebase Web SDK v9+
const idToken = await auth.currentUser.getIdToken(/* forceRefresh */ true)

A request with an expired or malformed token returns 401 Unauthorized with an invalid_token error code — refresh and retry once. See Errors for the full envelope.

Setting up your Firebase tenant

Each Hapana corporate is backed by a dedicated Firebase tenant (Google Identity Platform multi-tenancy). To wire members up:

  1. Ask Hapana for your corporate's Firebase project ID and tenant ID (surfaced in Control Center → API page).
  2. Initialise the Firebase SDK in your app with that project, and set the tenant on the auth instance: auth.tenantId = <your-tenant-id>.
  3. Sign the member in with any enabled provider, then call getIdToken() to get the bearer token for the API.

Testing without building an app

You don't need a finished mobile app to try the API. The Hapana Control Center → API page includes a token generator: sign in as a test member and it returns a live Firebase ID token you can paste into curl, Postman, or the interactive reference. The downloadable Postman collection includes a sign-in request that mints the token for you and sets it on every subsequent call.

Not using Firebase for your member identity? A delegated, server-to-server auth model (partner credential → short-lived member token) is planned for a later phase so you can integrate without adopting the Firebase client SDK. If that blocks you today, email api-support@hapana.com.