Authentication
How requests to the API identify their caller.
bearerAuthhttp · bearer · JWT
OIDC access token issued by one of this deployment's registered sign-in providers. Their issuers are listed in the protected resource metadata at /.well-known/oauth-protected-resource (RFC 9728), which every 401 challenge links to.
Authorization: Bearer <access token>cronSecrethttp · bearer
The deployment's `CRON_SECRET` environment variable, as Vercel Cron presents it. Only the notification schedule tick and the AI search index tick accept it.
Authorization: Bearer <access token>Endpoints marked public are served without an access token. Beyond a valid token, most endpoints also require one of the permissions granted through department roles.
A program — a Claude Code session, a CI job, a script — can hold an account of its own and obtain its tokens without a browser, through the provider's client credentials grant; the service accounts page walks through setting one up.
Two public endpoints carry their credential in the URL instead, because the clients that call them cannot send an Authorization header. SCORM package content is served under a short-lived, signed ticket that the course launch returns. A calendar feed, GET /api/calendar-feeds/{token}/calendar.ics, is authorized by the secret token in its path: calendar apps such as Outlook fetch subscribed calendars from their own servers, with no way to sign in. That URL is returned once, when POST /api/users/me/calendar-feeds creates the link, and works for anyone holding it until the link is revoked.