openapi: 3.0.1 info: title: Bytebase Auth API description: Bytebase exposes a Connect/gRPC API that is also served as a RESTful HTTP API via gRPC transcoding (google.api.http annotations). Every action in the Bytebase web console is backed by this API. This document models the core RESTful HTTP surface - instances, databases, projects, issues (schema change / migration), plans, rollouts, sheets, users, roles, groups, and project webhooks. Authentication uses a short-lived access token obtained by logging in with a service account; the token is supplied as a Bearer token in the Authorization header. The server URL is the base of your own self-hosted or cloud Bytebase deployment (the public demo is shown). termsOfService: https://www.bytebase.com/terms contact: name: Bytebase Support url: https://www.bytebase.com/docs/ version: v1 servers: - url: https://demo.bytebase.com/v1 description: Bytebase public demo (replace with your own deployment host) security: - bearerAuth: [] tags: - name: Auth paths: /auth/login: post: operationId: login tags: - Auth summary: Exchange service-account credentials for an access token. security: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LoginRequest' responses: '200': description: Access token issued. content: application/json: schema: $ref: '#/components/schemas/LoginResponse' components: schemas: LoginResponse: type: object properties: token: type: string description: Bearer access token used in the Authorization header. mfaTempToken: type: string LoginRequest: type: object properties: email: type: string example: my-service-account@service.bytebase.com password: type: string description: The service account's service key. web: type: boolean securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'Access token obtained from POST /v1/auth/login using a service-account email and service key. Supplied as `Authorization: Bearer `.'