---
title: "Authenticate. For internal use."
slug: "authenticate-for-internal-use-1"
updated: 2026-03-02T22:30:52Z
published: 2026-03-02T22:35:48Z
canonical: "support.appgate.com/authenticate-for-internal-use-1"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.appgate.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate. For internal use.

Post/authentication

API Scripts are recommended to use the Login call instead of separate Authentication & Authorization calls.

First step for logging in is sending the credentials and retrieving partial AuthToken. If the response has the "needTwoFactorAuth:true", then either API user must be extempt from Admin MFA or two-step MFA process must be completed before Authorization.

SecurityHTTPType bearer

Body parameters

Login Credentials.

<select class='api-response-data' aria-label='Media type'><option value='b4d8d78b-2270-4f93-943e-30553a4fb200'>application/json</option>
</select>object  providerNamestring    Required

Display name of the Identity Provider name.

Exampleldap
usernamestring    

Username. Required if a credentials based Identity Provider is used.

Exampleuser
passwordstring    

Password. Required if a credentials based Identity Provider is used.

ExampletSW3!QBv(rj{UuLY
deviceIdstring  (uuid)    Required

UUID to distinguish the Client device making the request. It is supposed to be same for every login request from the same server.

Example4c07bc67-57ea-42dd-b702-c2d6c45419fc
samlResponsestring    

SAMLResponse received from SAML provider. Required if a SAML based Identity Provider is used.

idTokenstring    

ID Token received from OIDC provider. Required if an OIDC based Identity Provider is used.

accessTokenstring    

Access Token received from OIDC provider. Required if an OIDC based Identity Provider is used.

Responses200

Login Response.

<select class='api-response-data' aria-label='Media type'><option value='35c816cd-3c4e-4e09-9796-9810f42adb28'>application/json</option>
</select>Expand Allobject  userobject  

Information about logged in user, such as username and email address, if exists.

namestring    

Username.

Exampleadmin
needTwoFactorAuthboolean    

If true, it is not possible to complete login process without providing MFA.

Examplefalse
canAccessAuditLogsboolean    

Whether there is a LogServer deployed and the user has privileges to access to it.

privileges Array of object (AdministrativePrivilege)   

The privileges the user has.

object  

Administrative Privilege item. Use type-target-map API to get the details on which types are valid for which targets and their scopes.

typestring    

The type of the Privilege defines the possible administrator actions.

Valid values[
  "All",
  "View",
  "Create",
  "Edit",
  "Tag",
  "Delete",
  "Revoke",
  "Export",
  "Upgrade",
  "RenewCertificate",
  "DownloadLogs",
  "Test",
  "GetUserAttributes",
  "Backup",
  "CheckStatus",
  "Reevaluate",
  "Reboot",
  "AssignFunction"
]
targetstring    

The target of the Privilege defines the possible target objects for that type.

Valid values[
  "All",
  "Appliance",
  "Condition",
  "CriteriaScript",
  "Entitlement",
  "AdministrativeRole",
  "IdentityProvider",
  "MfaProvider",
  "IpPool",
  "LocalUser",
  "ServiceUser",
  "Policy",
  "Site",
  "DeviceClaimScript",
  "EntitlementScript",
  "RingfenceRule",
  "ApplianceCustomization",
  "TrustedCertificate",
  "UserClaimScript",
  "OtpSeed",
  "Fido2Device",
  "Blacklist",
  "License",
  "UserLicense",
  "RegisteredDevice",
  "AllocatedIp",
  "SessionInfo",
  "AuditLog",
  "AdminMessage",
  "GlobalSetting",
  "CaCertificate",
  "File",
  "AutoUpdate",
  "RiskModel",
  "Ztp",
  "ClientProfile",
  "Secret",
  "DiscoveredApp"
]
scopeobject  

The scope of the Privilege. Only applicable to certain type-target combinations. Some types depend on the IdP/MFA type, such as GetUserAttributes. This field must be omitted if not applicable.

allboolean    

'If "true", all objects are accessible. For example, "type: Edit - target: Condition - scope.all: true" means the administrator can edit all Conditions in the system.'

ids Array of string   

Specific object IDs this Privilege would have access to.

string  (uuid)    Example4c07bc67-57ea-42dd-b702-c2d6c45419fc
tags Array of string   

Object tags this privilege would have access to.

string    Exampletag

defaultTags Array of string   

The items in this list would be added automatically to the newly created objects' tags. Only applicable on "Create" type and targets with tagging capability. This field must be omitted if not applicable.

string    Exampleapi-created
functions Array of string (ApplianceFunction)   

Privilege for changing Appliance Functions. Only applicable on "AssignFunction" type with Appliance or All target. This field must be omitted if not applicable.

string    Valid values[
  "Controller",
  "Gateway",
  "LogServer",
  "LogForwarder",
  "Connector",
  "Portal",
  "Metrics Aggregator",
  "Connection Broker"
]

tokenstring    

The AuthToken required for subsequent API calls.

expiresstring  (date-time)    

Token expiration time.

messageOfTheDaystring    

Message of the day configured by an admin.

ExampleWelcome to Appgate SDP.
ztpCollectiveTypestring    

ZTP type of the collective.

Valid values[
  "hosted",
  "connected"
]
ztpAccountTypestring    

ZTP account type.

Valid values[
  "standard",
  "demo"
]
crlEnabledboolean    

Whether X509 CRL is enabled for the system or not. Issued Certificates is disabled if it's not enabled.

400

JSON error. Check the JSON format.

<select class='api-response-data' aria-label='Media type'><option value='ef8bd2bf-348a-4214-a78e-8501431ad55a'>application/json</option>
</select>object  

Generic HTTP error.

idstring    

Machine readable error code.

messagestring    

Human readable error details.

401

Login Failed.

<select class='api-response-data' aria-label='Media type'><option value='d3ef4f35-430f-4228-b6e9-a7dc132db739'>application/json</option>
</select>object  idstring    

Machine readable error code.

messagestring    

Human readable error details.

reasonstring    

The authentication failure reason.

ExampleInvalid username or password.

406

Invalid 'Accept' header.

<select class='api-response-data' aria-label='Media type'><option value='8664531d-ceeb-4523-86a2-39860ad46584'>application/json</option>
</select>object  

Generic HTTP error.

idstring    

Machine readable error code.

messagestring    

Human readable error details.

422

Request validation error. Check "errors" array for details.

<select class='api-response-data' aria-label='Media type'><option value='2e44e5b6-1a0d-41eb-8349-e81378db84c7'>application/json</option>
</select>Expand Allobject  

Http 422 error for object validation.

idstring    

Machine readable error code.

messagestring    

Human readable error details.

errors Array of object   

List of fields with validation errors.

object  fieldstring    

Name of the field that failed validation.

Examplename
messagestring    

Failure reason.

Examplemay not be null

500

Unexpected server side error.

<select class='api-response-data' aria-label='Media type'><option value='e96c9c98-76bb-4a32-9379-2d031f1c814f'>application/json</option>
</select>object  

Generic HTTP error.

idstring    

Machine readable error code.

messagestring    

Human readable error details.
