openapi: 3.0.1 info: title: Preset Authentication API description: 'Specification of the Preset API. Preset is a managed cloud BI and analytics platform powered by Apache Superset. The API has two surfaces: the Preset Manager API at https://api.app.preset.io (authentication, teams, workspaces, guest tokens) and a per-workspace proxy to the underlying Apache Superset REST API reached at the workspace hostname pattern {workspace-slug}.{region}.app.preset.io. Authenticate by exchanging an API token name and secret at POST /v1/auth/ for a JWT, then pass it as a Bearer token on subsequent requests.' termsOfService: https://preset.io/terms-and-conditions/ contact: name: Preset Support url: https://docs.preset.io version: '1.0' servers: - url: https://api.app.preset.io description: Preset Manager API (authentication, teams, workspaces, guest tokens) - url: https://{workspaceSlug}.{region}.app.preset.io description: Per-workspace proxy to the Apache Superset REST API variables: workspaceSlug: default: my-workspace description: The workspace slug returned by the workspaces endpoint region: default: us2a description: The workspace region (e.g. us2a) tags: - name: Authentication paths: /v1/auth/: post: operationId: createToken tags: - Authentication summary: Exchange API token credentials for a JWT access token description: Exchanges an API token name and secret (generated in Preset account settings) for a short-lived JWT access token valid for a few hours. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AuthRequest' responses: '200': description: A JWT access token payload. content: application/json: schema: $ref: '#/components/schemas/AuthResponse' '401': description: Invalid credentials. components: schemas: AuthRequest: type: object required: - name - secret properties: name: type: string description: The API token name from Preset account settings. secret: type: string description: The API token secret. AuthResponse: type: object properties: payload: type: object properties: access_token: type: string description: The JWT access token used as a Bearer token. securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'JWT obtained from POST /v1/auth/ by exchanging an API token name and secret. Passed as Authorization: Bearer .'