Call the Casdoor API
This guide explains how to authenticate to the Casdoor REST API and call it from your own applications, services, and scripts.
Learning outcomes
- Choose the authentication method that fits your caller.
- Send an access token, client credentials, or an access key with a request.
- Get an access token for a service without a user.
- Sign a user out of all sessions through the API.
- Allow your frontend origin to call the API from a browser.
What you need
- A running Casdoor instance. The examples use the demo site
https://door.casdoor.com. - An application in Casdoor, with its client ID and client secret
About the Casdoor API
The Casdoor admin console is a React single-page application that calls a REST API. Your code can call the same API, so everything that the console does is available over HTTP. The API has three kinds of callers:
- The Casdoor frontend
- The Casdoor SDKs, such as casdoor-go-sdk
- Your own applications and scripts
The API reference is the Swagger page of your Casdoor instance, for example https://door.casdoor.com/swagger. To regenerate the Swagger files, see Generate Swagger files.
Choose an authentication method
| Method | The request runs as | Use it for |
|---|---|---|
| Access token | The user who signed in, or the application for a client credentials token | Applications that act for a signed-in user, and services that hold a token |
| Client ID and client secret | The application, with the rights of an administrator of its organization | Machine-to-machine (M2M) calls from backend services, CLIs, and scheduled jobs |
| Access key and access secret | The organization, application, or user that the key belongs to | Scripts and integrations that need a long-lived credential |
| Username and password | The user | Local demos and compatibility only |
Authenticate with an access token
An access token is what your application receives when a user signs in through OAuth 2.0. A request that carries the token runs with the permissions of that user.