Skip to main content
POST
Authenticate with API Key

Overview

Authenticates using a GUID API key stored in Telemax, or a legacy non-GUID key resolved via the configured legacy API service. Returns a JWT including API key claims (Actions, Vehicles, DateFormat, etc.) when applicable.
A V2 version of this endpoint is available: API key token. New integrations should prefer V2.

Endpoint

POST /api/Authentication/token/api-key

Authentication

Not required.

Request headers

Request body (form)

string
required
API key string (GUID format or legacy format).

Example request body

Response

200 OK — same JwtTokenResponse shape as user login.

Error responses

Authorizations

Authorization
string
header
required

JWT Bearer token obtained from POST /api/authentication/token/user or POST /api/authentication/token/api-key.

Lifetime: ~24 hours (86,399 seconds). Cache the token and reuse it. Re-authenticate 5 minutes before expiry.

Scoping:

  • User tokens are scoped to a single company.
  • API key tokens may restrict access to a vehicle allowlist and/or action set (see token claims).

No refresh endpoint — re-authenticate with your credentials when the token expires.

Headers

Content-Type
string

Standard and must keep it as it is.

Body

application/x-www-form-urlencoded
apiKey
string
required

API key

Example:

"your_api_key_here"

Response

Successful response

access_token
string

JWT access token

Example:

"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."

token_type
string
Example:

"Bearer"

expires_in
number<float>

Token lifetime in seconds. Default is 86399.0 (≈24 hours). Cache and reuse this token until near expiry — do not request a new token per API call.

Example:

86399