Authentication
All requests to the Zorya API are authenticated using a Bearer Token (JWT) obtained via your Zorya Portal credentials. Only the login endpoint is public; every other endpoint requires the token.
Step 1: Register and Obtain Credentials
- Go to https://app.zorya.com/register and complete the registration form at the https://app.zorya.com/.
- After registration, copy your
usernameandpasswordfrom the portal.
Step 2: Generate a Token from the Docs
You can generate your token without leaving this documentation:
- Open the API Reference and go to USERS & SESSIONS → Get a signed token for a user (
POST /api/v1/User/login). - Click the Test button (with the play icon) in the panel on the right.
- The Body section already contains a valid example — just replace
<YOUR_USERNAME>and<YOUR_PASSWORD>with your portal credentials (if the Body is empty, click Use Example → default to load it): - Press Send.
Code
The 200 response looks like this — your token is the value of the data field:
Code
Tokens are valid for 24 hours. After expiration, repeat this step to get a new one.
The same request as cURL, for use outside the docs:
curl -X POST "https://gateway.zorya.com/api/v1/User/login" \
-H "Content-Type: application/json" \
-d '{
"username": "<YOUR_USERNAME>",
"userPassword": "<YOUR_PASSWORD>"
}'
Step 3: Using Your Bearer Token
Pass the token in the Authorization header of all subsequent requests:
Code
To try it from the docs: open any authenticated endpoint (for example USERS & SESSIONS → Get the current active user, GET /api/v1/User/me), click Test, open the Authentication section, select the BearerAuth scheme, paste your token, and press Send. A 200 response with your user profile confirms everything works.
curl -X GET "https://gateway.zorya.com/api/v1/User/me" \
-H "Authorization: Bearer <YOUR_ACCESS_TOKEN>"
New to the interactive docs? Read Using the API Reference for a guided tour of the Test dialog, request types, and where path, query, header, and body values go.
Security Best Practices
- Rotate Credentials Periodically: Update your password and re-authenticate regularly via the portal.
- Use HTTPS Only: All unencrypted HTTP requests will be automatically rejected.
- Keep Tokens Secure: Never commit tokens to version control or expose them in client-side applications.
Need help? Contact support@zorya.com.