Intron Connect

Authentication

API key, JWT, or HMAC — pick by caller.

Connect authenticates three ways. Pick one per caller; do not mix on the same request.

ModeHeaderUse when
API keyX-API-KEY: <key>Machine clients registered as consumers
JWTAuthorization: Bearer <token>People and internal tools (Portal, Try it)
HMACX-Partner-SignaturePartner inbound webhooks — Sign requests

API keys

  1. An operator registers a consumer and copies the key once.
  2. Assign grants for catalog artifacts (for example contact-leads).
  3. Call published Experience paths through the gateway.
curl -sS \
  -H "X-API-KEY: $CONNECT_API_KEY" \
  "https://connect.intronsoft.com/api/v1/leads?limit=10"

Ops (/api/v1/ops/**) stays JWT. Keys do not open the portal.

JWT

Authentik issues tokens (authorization code + PKCE for browsers). JWT callers with Developer, Operator, or Admin bypass consumer-grant checks. Machine OAuth is possible; most integrators should use a key.

Try-it on this site uses the public intron-connect client. No client secret is embedded in the docs image.

HMAC

Partners sign the raw body. No Authentik account. See Sign requests.

If this fails

SymptomCause
401Missing/expired JWT, or HMAC mismatch
403Authenticated but role or grant missing
Key works on ping, fails on leadsNo contact-leads grant

Next: Consumers · Roles

On this page