Authenticate requests and provide the tenant context expected by FeraRender.
Overview
Authenticate requests and provide the tenant context expected by FeraRender. API clients must be tenant-aware, permission-aware, and capable of handling both JSON and binary responses.
Key points
- Send x-auth-token on protected routes.
- Send the instance UUID for tenant-scoped operations.
- Some service-to-service calls may forward x-api-key.
- Tokens are verified as JWTs.
- A missing or invalid token returns 401.
- Do not expose service credentials in browser code.
Example
curl "<render-base-url>/api/v1/templates" \
--header "x-auth-token: <token>" \
--header "instance: <instance-uuid>"
Replace bracketed values with values issued for the target environment. Never place production tokens, API keys, or client data in screenshots or public examples.
Recommended procedure
- Send authentication and instance headers.
- Validate the request body before transmission.
- Inspect HTTP status, content type, and structured errors.
- Log non-sensitive identifiers needed to reproduce failures.
Client requirements
- Check the HTTP status before processing the body.
- Check
Content-Typebefore deciding whether the response is JSON, DOCX, or PDF. - Do not log authentication tokens or complete client document data.
- Preserve the instance context through every Feradel service-to-service call.
- Treat validation and compilation errors as input or template defects rather than transient network failures.
Troubleshooting
A client treats an error as a file
Check HTTP status and Content-Type before writing the response body to disk.
The same request works in another tenant
Compare instance, owner, token permissions, and object UUIDs.
A route returns an unexpected envelope
The current controllers are not fully standardized; handle HTTP status and documented fields defensively.
Related documentation
- API Authorization and Tenant Scoping
- API Request, Response, and Error Conventions
- Template API Reference
Documentation source: feradelinc/feradel.render.api, reviewed against repository revision b2c3a710. Verify behavior against the deployed release before publishing exact routes, limits, or version requirements.