1. AuditDashboard API v2
AuditDashboard Developer Portal
  • AuditDashboard API v2
    • AuditDashboard APIs
    • Open API V2 Authentication
    • Clients
      • Get All Clients
      • Create Clients
      • Update Clients
      • Deactivate Clients
      • Activate Clients
      • Client Details
      • Update Client
      • Deactivate Client
      • Activate Client
    • Users
      • /api/v2/query
      • /api/v2/list
      • Get Users by Status
      • Create Users
      • Update Multiple Users
      • Deactivate Users
      • Activate Users
      • Get User Details
      • Update User Details
      • Deactivate User
      • Activate User
      • Invite Users
      • Generate User Activity Report
    • Divisions
      • Get Active Divisions
    • Engagements
      • Get Engagements by Status
      • Create Engagements
      • Update Engagement
      • Update Engagement Statuses
      • Delete Engagements
      • Get My Engagements
      • Get My Overdue Engagements
      • Get Engagements Ready To Complete
      • Get Engagement Details
      • Update Engagement
      • Update Engagement Status
      • Delete Engagement
      • Duplicate Engagement
      • Download Engagement Documents
      • Get Engagement Activity Feed
      • Download Engagement Request Report
      • Download 'All Engagements' Report
    • Files
      • List Containers
      • Create Company Cabinet
      • Set Container Notifications
      • Update Folder
      • Delete Folder
      • List Folders in Container
      • Create Folder
      • List Files in Container Root
      • Upload File to Container
      • List Files in Folder
      • Upload File to Folder
      • Share File or Folder
      • Unshare File or Folder
      • Delete Cabinet
      • Download File
      • Download Folder Contents
      • Create Download Group
    • Insights
      • Get Engagement by Last Activity Report Parameters
      • Engagement by Last Activity
      • User Activity and Status
    • Me
      • Get Current User
    • Requests
      • Get Engagement Requests
      • Get Requests Pending My Review
      • Get My Requests
      • Get My Overdue Requests
      • Get Requests I've Flagged
      • Get Request by ID
      • Update Request Details
      • Update Request Status and Priority
      • Delete Request
      • Create Requests
      • Update Multiple Requests
      • Update Request Status and Priority
      • Delete Multiple Requests
      • Get Request History Feed
      • Get Request Activity Feed
      • Get Mentionable Users for a Request
      • Add Comment to Request
      • Send Files to Engagement
      • Delete a Request Comment
      • Delete a Request Document
      • Download Request Documents
      • Update Multiple Request Restrictions
      • Update Single Request Restrictions
      • Upload Request Document
    • Trash
      • Get Trash Types
      • Get Trash List
      • Restore Trash Items
      • Restore a Trash Item
    • Schemas
      • AccessType
      • AddressFamily
      • AggregateFunction
      • APIActivityFeedPageModel
      • APIBatchItemResult
      • APICompanyCreateModel
      • APICompanyModel
      • APICompanyUpdateModel
      • APIContainerCreateModel
      • APIContainerModel
      • APIDivisionModel
      • APIEngagementAutomationsModel
      • APIEngagementCreateModelV2
      • APIEngagementDuplicateModelV2
      • APIEngagementModelV2
      • APIEngagementMonthlyReportModel
      • APIEngagementStatusUpdateModel
      • APIEngagementSummaryModelV2
      • APIEngagementUpdateAutomationsModel
      • APIEngagementUpdateModelV2
      • APIEngagementUser
      • APIFeedItemModel
      • APIFileModel
      • APIFileTransferRequestModel
      • APIFileTransferResponseModel
      • APIFileTransferResultModel
      • APIFolderCreateModel
      • APIFolderModel
      • APIFolderUpdateModel
      • APIMeDivisionModel
      • APIMeModel
      • APIMentionableUserModel
      • APIMeRoleModel
      • APIRequestCreateModel
      • APIRequestModel
      • APIRequestRestricModel
      • APIRequestUpdateModel
      • APIShareRequestModel
      • APIStatusModel
      • APITrashModel
      • APIUserCreateModel
      • APIUserModel
      • APIUserUpdateModel
      • AsnEncodedData
      • AsymmetricAlgorithm
      • AuthenticationProvider
      • AutomationTrigger
      • BatchItemOutcome
      • CalculationExpression
      • CalculationOperator
      • CancellationToken
      • Claim
      • ClaimsIdentity
      • ClaimsPrincipal
      • ColumnFormatOptions
      • ColumnInfo
      • ConnectionInfo
      • CreateDownloadGroupRequest
      • EngagementNotificationType
      • EngagementStatus
      • ETag
      • FeedItem
      • FeedType
      • FileType
      • HostString
      • HttpContext
      • HttpRequest
      • HttpResponse
      • IFormFile
      • IIdentity
      • IPAddress
      • IResponseCookies
      • IServiceProvider
      • ISession
      • KeySizes
      • KeyValuePairOfstringAndstring
      • KeyValuePairOfstringAndStringValues
      • KeyValuePairOfTypeAndObject
      • MultiFactorType
      • NotificationFrequency
      • ObjectReference
      • Oid
      • PagedResultOfAPICompanyModel
      • PagedResultOfAPIContainerModel
      • PagedResultOfAPIEngagementModelV2
      • PagedResultOfAPIEngagementSummaryModelV2
      • PagedResultOfAPIFileModel
      • PagedResultOfAPIFolderModel
      • PagedResultOfAPIRequestModel
      • PagedResultOfAPIUserModel
      • PathString
      • Permission
      • PermissionList
      • PermissionType
      • PipeReader
      • PipeWriter
      • ProblemDetails
      • PublicKey
      • QueryColumn
      • QueryRequest
      • QueryString
      • ReadOnlyMemoryOfbyte
      • RequestNotificationType
      • RequestStatus
      • SafeWaitHandle
      • SetContainerNotificationsRequest
      • SetContainerNotificationsResponse
      • SqlDbType
      • Stream
      • TableInfo
      • TrackingInfo
      • TrashType
      • Type
      • WaitHandle
      • WebSocketManager
      • X500DistinguishedName
      • X509Certificate2
      • X509Extension
  • AuditDashboard API v1
    • Clients
      • Get All Clients
      • Create Clients
      • Update Clients
      • Deactivate Clients
      • Activate Clients
      • Client Details
      • Update Client
      • Deactivate Client
      • Activate Client
    • Divisions
      • Get Active Divisions
    • Engagements
      • Get Engagements by Status
      • Create Engagements
      • Update Engagement
      • Update Engagement Statuses
      • Delete Engagements
      • Get Engagement Details
      • Update Engagement
      • Update Engagement Status
      • Delete Engagement
      • Download Engagement Documents
      • Download Engagement Request Report
      • Download 'All Engagements' Report
      • /api/public/engagements/{engagementID}/activityFeed
      • /api/public/engagements/{engagementID}/requestlistreportdata
    • Insights
      • Get Engagement Activity Log Parameters
      • Engagement Activity Log
      • Get Engagement by Last Activity Report Parameters
      • Engagement by Last Activity
      • Get Active Professional Users for Schedule
      • User Activity and Status
      • Schedule
    • Requests
      • Get Engagement Requests
      • Get Request by ID
      • Update Request Details
      • Update Request Status and Priority
      • Delete Request
      • Create Requests
      • Update Multiple Requests
      • Update Request Status and Priority
      • Delete Multiple Requests
      • Get Request History Feed
      • Get Request Activity Feed
      • Add Comment to Request
      • Delete a Request Comment
      • Delete a Request Document
      • Download Request Documents
      • Update Multiple Request Restrictions
      • Update Single Request Restrictions
      • Upload Request Document
    • Users
      • Get Users by Status
      • Create Users
      • Update Multiple Users
      • Deactivate Users
      • Activate Users
      • Get User Details
      • Update User Details
      • Deactivate User
      • Activate User
      • Invite Users
      • Generate User Activity Report
    • Authorization
      • Authorization call for Bearer Token
    • Trash
      • Get Trash Types
      • Get Trash List
      • Restore Trash Items
      • Permanently deletes trash items.
      • Restore a Trash Item
      • Permanently deletes a trash item.
    • Files
      • List Containers
      • Set Container Notifications
      • List Folders in Container
      • List Files in Container Root
      • List Files in Folder
      • Share File or Folder
      • Unshare File or Folder
      • Download File
      • Download Folder Contents
      • Create Download Group
    • Schemas
      • Schemas
      • v2
      • v1
      • APICompanyCreateModel
      • APICompanyModel
      • APICompanyUpdateModel
      • APIEngagementActivityLogModel
      • APIContainerModel
      • APIEngagementCreateModel
      • APIEngagementModel
      • APIEngagementMonthlyReportModel
      • APIEngagementUpdateModel
      • APIEngagementUser
      • APIRequestCreateModel
      • APIRequestModel
      • APIFileModel
      • APIRequestRestricModel
      • APIFolderModel
      • APIRequestUpdateModel
      • APIUserCreateModel
      • APITrashModel
      • APIUserModel
      • APIUserUpdateModel
      • AuthenticationProvider
      • APIShareRequestModel
      • ETag
      • EngagementNotificationType
      • EngagementStatus
      • FeedItem
      • FeedType
      • AccessType
      • MultiFactorType
      • AddressFamily
      • NotificationFrequency
      • AsnEncodedData
      • ProblemDetails
      • Assembly
      • RegistrationStatus
      • AsymmetricAlgorithm
      • RequestNotificationType
      • RequestStatus
      • ByteReadOnlyMemory
      • TrackingInfo
      • ByteReadOnlySpan
      • CallingConventions
      • TrashType
      • CancellationToken
      • Claim
      • ClaimsIdentity
      • ClaimsPrincipal
      • ConnectionInfo
      • ConstructorInfo
      • CreateDownloadGroupRequest
      • CustomAttributeData
      • CustomAttributeNamedArgument
      • CustomAttributeTypedArgument
      • EventAttributes
      • EventInfo
      • FieldAttributes
      • FieldInfo
      • FileType
      • GenericParameterAttributes
      • HostString
      • HttpContext
      • HttpRequest
      • HttpResponse
      • ICustomAttributeProvider
      • IIdentity
      • IPAddress
      • IResponseCookies
      • IServiceProvider
      • ISession
      • IntPtr
      • KeySizes
      • LayoutKind
      • MemberInfo
      • MemberTypes
      • MethodAttributes
      • MethodBase
      • MethodImplAttributes
      • MethodInfo
      • Module
      • ModuleHandle
      • Oid
      • ParameterAttributes
      • ParameterInfo
      • PathString
      • PipeWriter
      • PropertyAttributes
      • PropertyInfo
      • PublicKey
      • QueryString
      • RuntimeFieldHandle
      • RuntimeMethodHandle
      • RuntimeTypeHandle
      • SafeWaitHandle
      • SecurityRuleSet
      • SetContainerNotificationsRequest
      • SetContainerNotificationsResponse
      • StringStringKeyValuePair
      • StringStringValuesKeyValuePair
      • StructLayoutAttribute
      • Type
      • TypeAttributes
      • TypeInfo
      • TypeObjectKeyValuePair
      • WaitHandle
      • WebSocketManager
      • X500DistinguishedName
      • X509Certificate2
      • X509Extension
  1. AuditDashboard API v2

Open API V2 Authentication

AuditDashboard Open API v2 — Authentication#

The v2 API (/api/v2/*) authenticates with a JWT bearer token obtained through an interactive OAuth loopback flow: a real user signs in through their SSO provider (Microsoft / Google) and your app receives a bearer and a refresh token. Every call is made as that user and is scoped to their permissions.
Once you hold a bearer token, every v2 request carries it the same way:
Authorization: Bearer {token}

Loopback OAuth flow#

1. Open the login URL in a browser#

https://{tenant}.auditdashboard.{suffix}/Account/Login/{provider}?returnUrl=http://127.0.0.1:{port}/
{tenant} — portal subdomain (e.g. yoursite)
{suffix} — (e.g. com)
{provider} — Microsoft or Google
returnUrl — a loopback listener you control
Local dev example:
https://yoursite.auditdashboard.com/Account/Login/Microsoft?returnUrl=http://127.0.0.1:8123/
The user completes SSO in the browser.

2. Receive the one-time code on your loopback listener#

Because returnUrl is a genuine loopback address, the server does not set a cookie. Instead it mints a short-lived one-time code and redirects the browser to:
http://127.0.0.1:{port}/?code={code}
Your local HTTP listener reads code from the query string.
The code is single-use and expires 2 minutes after it is issued.
Only real loopback hosts trigger this: 127.0.0.0/8, localhost, ::1, http scheme only. The host is validated by parsing the URL (not a string prefix), and embedded credentials (http://127.0.0.1@evil.com) are rejected — so a code is never handed to an external host. Any non-loopback returnUrl falls through to normal cookie sign-in and no code is minted.

3. Exchange the code for tokens#

POST /api/account/exchangeToken
Content-Type: application/json

{
    "code": "96534024690e470eaa70d966d56c1c49"
}
No auth header is required on this call — the code is the credential.
(POST /api/account/outlookToken is a legacy alias that behaves identically; new clients should use exchangeToken.)
curl:
Response (200 OK):
{
    "token": "<JWT access token>",
    "expires": "2026-08-06T12:34:56Z",
    "refreshToken": "<opaque refresh token>",
    "refreshExpires": "2026-08-13T12:34:56Z",
    "email": "user@example.com",
    "userid": 123,
    "name": "Jane Doe",
    "roles": [ ... ],
    "companyName": "...",
    "customerPortalName": "..."
}
A missing, expired, already-used, or unknown code returns 401 Unauthorized.

4. Call the API#


Refreshing the access token#

Access tokens are short-lived; the refresh token lasts 7 days. When the access token expires:
POST /api/account/refresh
Content-Type: application/json

{
    "refreshToken": "<opaque refresh token>"
}
Returns the same body shape as exchangeToken with a fresh token and a rotated refreshToken — the old refresh token is revoked on use, so always store the new one. An invalid, revoked, or expired refresh token returns 401.

Summary#

StepMethodRouteAuth
LoginGET (browser)/Account/Login/{provider}?returnUrl=http://127.0.0.1:{port}/interactive SSO
Exchange codePOST/api/account/exchangeTokenthe one-time code (no header)
RefreshPOST/api/account/refreshthe refresh token (no header)
API callsany/api/v2/*Authorization: Bearer {token}
Modified at 2026-09-09 22:11:40
Previous
AuditDashboard APIs
Next
Get All Clients
Built with