Anythink authentication is built to be simple to integrate and secure by default. Users can sign in with email and password or Google, your app receives a JWT that controls exactly what they can see and do, and role-based access rules determine which data each user is allowed to touch.
When a user signs in, Anythink returns a JSON Web Token (JWT). Your app passes this token with every subsequent API request. Anythink verifies the token, identifies the user, and applies whatever role-based and row-level access rules you have configured — automatically, on every request.
There are two sides to this:
Both are handled by Anythink. You configure the rules once in your dashboard; the platform enforces them on every API call.
The default method. Users register with an email address and password, and receive a confirmation email before their account is activated.
Register a new user:
POST /org/{orgId}/auth/v1/register
Content-Type: application/json
{
"first_name": "Alice",
"last_name": "Smith",
"email": "alice@example.com",
"password": "securepassword"
}
Log in:
POST /org/{orgId}/auth/v1/token
Content-Type: application/json
{
"email": "alice@example.com",
"password": "securepassword"
}
Both return an access_token (JWT) and a refresh_token.
Users can sign in with their Google account. You configure the integration once in your Anythink dashboard, and Anythink handles the full OAuth flow.
Setting up Google sign-in:
https://your-instance.anythink.cloud/org/{orgId}/auth/v1/google/callbackOnce configured, your app initiates the flow by redirecting users to the Google authorisation URL, and Anythink exchanges the resulting code for a JWT automatically.
Once a user is signed in, include their JWT as a Bearer token in every API request:
GET /org/{orgId}/orders
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
Anythink uses this token to:
If you make a request without a token, or with an expired token, you get a 401 Unauthorized response.
Some data you may want to be publicly accessible — product listings, published articles, pricing. For these, use the public search endpoint which requires no token:
GET /org/{orgId}/search/public?q=*&e=products
Everything else requires a valid JWT.
Access tokens expire after a short period. Use the refresh token to get a new access token without asking the user to log in again:
POST /org/{orgId}/auth/v1/refresh
Content-Type: application/json
{
"token": "your-refresh-token"
}
Returns a new access_token. Store refresh tokens securely — they are long-lived.
For server-to-server integrations — workflows, scripts, or backend services — you can use an API key instead of a JWT. API keys are created in your dashboard under Settings → API Keys and take the format ak_....
Pass the key in the x-api-key header:
GET /org/{orgId}/customers
x-api-key: ak_your_key_here
API keys are scoped to your organisation and carry the permissions of the role they were created with. Keep them secret — treat them like passwords.
Roles control what authenticated users can do. Every user is assigned a role, and every role has a set of permissions on each entity — read, create, update, delete, or none.
This is configured in Settings → Roles & Permissions in your dashboard. See the Roles and Permissions doc for the full guide.
Beyond role-level permissions, you can restrict individual records to specific users. For example, a customer should only be able to see their own orders — not everyone else's.
Row-level security (RLS) is configured per entity and works automatically once enabled. When a user with an RLS-enabled entity makes a request, Anythink filters the results to only records that belong to them.
See the Roles and Permissions doc for setup details.