ejento.ai API
Stable
  • Stable
  • V2
  • V2 Legacy
Stable
  • Stable
  • V2
  • V2 Legacy
ejento.ai
Stable
  • Stable
  • V2
  • V2 Legacy
  1. Authentication
  • Overview
  • Changelog
  • Versioning
  • Quick-Start Template for Building an App
  • FAQs
  • Guides
    • Getting Started
      • How to generate API Key and Auth Token
      • Build an App with Ejento APIs
      • How to Import Ejento APIs into Postman
      • Authentication with Azure AD Token
      • Permission Sets
    • Migrations
      • Response API Migration
      • Indexing API Migration
    • Integrations
      • Voice Call API Integration Guide
      • Staging & Publishing for Agents API Guide
      • Chat Thread Attachment Integration Guide
  • Authentication
    • Getting Started with Authentication
    • Authentication and Token Refresh Guide
    • SSO
      • Initiate Google SSO Login
      • Initiate Microsoft SSO Login
      • Initiate LinkedIn SSO Login
      • Initiate Okta SSO Login
      • Exchange Azure AD Token for Ejento Tokens
    • Feature Flags
      • Get Login Feature Flags
    • Authenticate User
      POST
    • Request Passwordless Exchange Token
      POST
    • Exchange Passwordless Token for Access Tokens
      POST
    • Register User
      POST
    • Update Own Password
      PATCH
    • Refresh Access Token
      POST
    • Passwordless Authentication (Email Magic Link)
      POST
    • Validate Magic Link Token
      POST
    • Verify Email OTP
      POST
  • Agents
    • Agent Access
      • Get Agent Access
      • Update Agent Access
    • Agent Alias
      • Get Agent Alias
      • Create an Agent Alias
      • Update an Agent Alias
      • Delete an Agent Alias
      • Get all Agent Aliases
    • Agent Tags
      • Add or Remove Tags from an Agent
      • Get all Tags for a given Project or Organization
      • Get all Tags grouped by Agent for a given Project or Organization
    • Agent Chat Threads
      • Get Chat Threads of an Agent
      • Create Chat Thread for an Agent
    • Agent Comment
      • Get all Comments for an Agent
      • Create a Comment
      • Update a Comment
      • Delete a Comment
    • Agent Rating
      • Get Ratings of an Agent
      • Update Agent Rating
      • Get all Agent Ratings
    • Agent Review
      • Get all Reviews for specific Agent
      • Create a new Review
      • Get all Reviews of the Authenticated User
      • Update a Review
      • Delete a Review
    • Agent Tools
      • List all Tools with their enabled status for the given Agent
      • Unlink an Agent from a Tool
      • Link an Agent to a Tool
      • List all tools that are connected to the Agent
    • Agent Vote
      • Get Vote Information for an Agent
      • Vote on an Agent
    • Agent Type
      • Get all Agent Types
      • Get a specific Agent Type
      • Update a specific Agent Type
    • Evaluation Datasets
      • List Agent Evaluation Datasets
      • Create Agent Evaluation Dataset
      • Batch Delete Agent Evaluation Datasets
      • Get Agent Evaluation Dataset
      • Update Agent Evaluation Dataset
      • Delete Agent Evaluation Dataset
      • Upload Agent Evaluation Dataset (CSV/Excel)
    • Evaluation Runs
      • List Agent Evaluation Runs
      • Create Agent Evaluation Run
      • Batch Delete Agent Evaluation Runs
      • Get Agent Evaluation Run
      • Update Agent Evaluation Run
      • Delete Agent Evaluation Run
    • Agent Permissions
      • List all permissions on an agent
      • Grant permission on an agent
      • Update a permission on an agent
      • Revoke permission on an agent
      • Grant multiple permissions on an agent
      • Revoke multiple permissions on an agent
      • Get user permissions on a specific agent
      • Get user permissions on multiple agents
    • Agent Skills
      • Get all Skills available to an Agent
      • Unlink a Skill from an Agent
      • Link a Skill to an Agent
    • Get all Agents
    • Create a new Agent
    • Get an Agent
    • Update an Agent
    • Delete an Agent
    • Activate an Agent
    • Get Agent-Corpus Connections
    • Create Multiple Agent-Corpus Connections
    • Delete Agent-Corpus Connections
    • Get Agent-Corpus Connection Details
    • Create Agent-Corpus Connection
    • Update Agent-Corpus Connection
    • Delete Agent-Corpus Connection
    • Get agent history with pagination
    • Restore an agent to a previous checkpoint
    • Get a single agent history record by history ID
    • Create Custom Instructions for an Agent
    • Update Custom Instructions for an Agent
    • Delete a Custom Instruction for an Agent
    • Get Agent Prompt History
    • Create a Recent Agent
    • Delete a Recent Agent
    • Get Agent Details with Starred Status
    • Create Starred Agent
    • Delete Starred Agent
    • Get the Status of an Agent
    • Get all Character Voices
    • Get Agent Filter
    • Generate an image for an agent based on the provided description
    • Get all Agents by Project
    • Get list of Recent Agents
    • Get all workflows for an agent
    • Get all Starred Agents of the Authenticated User
    • Get Staging Diff
    • Get publish history for an agent
    • Get rollback diff preview for a publish record
    • Roll back staging agent to a previous publish
    • Publish staging agent to main
    • Clone an Agent
    • Get diff detail for a publish record
  • Agent Response
    • Stream Agent Response (SSE)
    • Generate Agent Response (Non-Streaming)
    • Generate Token for Voice Call
    • Get an Agent Response
    • Update an Agent Response
    • Delete an Agent Response
    • Get Comments for Agent Response
    • Create a Comment for Agent Response
    • Create a Feedback for an Agent Response
    • Pin an Agent Response
    • Unpin an Agent Response
    • Get Supporting Content of an Agent Response
    • Get Thoughts of an Agent Response
    • Get Agent Responses based on filters
    • Get Agent Responses of an Agent
    • Create Agent Response Log
    • Get Pinned Agent Responses
    • Create Bulk Agent Response Logs
    • Stop an in-flight streaming response
  • Chat Thread
    • Agent Response
      • Get Agent Responses for a Chat Thread
      • Delete Agent Responses for a Chat Thread
    • Chat Logs
      • Get Chat Logs for a Chat Thread
    • Corpus Connection
      • Get Corpus Connection by ChatThread ID
      • Delete Corpus Connection by ChatThread ID
      • Get a ChatThread-Corpus connection
      • Create a ChatThread-Corpus connection
      • Delete a ChatThread-Corpus connection
    • Documents
      • Get Documents in Chat Thread
    • Get Chat Thread
    • Update Chat Thread
    • Delete Chat Thread
    • Get Chat Threads based on various filters
    • Global Hybrid Search across Chat Threads and Chatlogs
    • Get Recent Chat Threads across all Agents
  • Chat Logs
    • Get Chat Log Details
    • Get Chat Log Search Results
  • Conversation Starters
    • Get Conversation Starters for an Agent
    • Create a new Conversation Starter.
  • Teams
    • Team Permissions
      • List all permissions on a team
      • Grant permission on a team
      • Update a permission on a team
      • Revoke permission on a team
      • Grant multiple permissions on a team
      • Revoke multiple permissions on a team
      • Get user permissions on a specific team
      • Get user permissions on multiple teams
    • Get all Teams
    • Create a Team
    • Get a Team
    • Update a Team
    • Delete a Team
    • Get all Projects of a Team
    • Create a Recent Team
    • Get all Users in a Team
    • Add Users to a Team
    • Remove User from Team
    • Get Recent Teams
    • Get all Teams of the Authenticated User
  • Projects
    • Project Permissions
      • List all permissions on a project
      • Grant permission on a project
      • Update a permission on a project
      • Revoke permission on a project
      • Grant multiple permissions on a project
      • Revoke multiple permissions on a project
      • Get user permissions on a specific project
      • Get user permissions on multiple projects
    • Retrieve all Projects
    • Create a Project
    • Get a Project
    • Update a Project
    • Delete a Project
    • Get Agent Responses using Project ID
    • Add a Recent Project for a User
    • Add Users to a Project
    • Remove a User from a Project
    • Get all Workflows for a Project
    • Get multiple Projects by their IDs
    • Get Projects based on filters
    • Get Recent Projects for a User
    • Get Projects with Team Details
  • Corpora
    • Corpus Permissions
      • Get all Permissions for a Corpus
      • Grant permission on a corpus
      • Update a permission on a corpus
      • Revoke permission on a corpus
      • Batch grant permissions on a corpus
      • Batch revoke permissions on a corpus
      • Get calling user's permissions on a corpus
      • Get a user's permissions on a corpus
      • Get a user's permissions across multiple corpora
    • Get all Corpus
    • Upload a Document to a Corpus
    • Create a Corpus
    • Get a Corpus
    • Update a Corpus
    • Delete a Corpus
    • Get Corpus Agent Connections
    • Get Default Corpus Agent Connection
    • Annotate/Tag a Corpus
    • Get Conversation Starters for a Corpus
    • Get all Documents for a Corpus
    • Delete Document(s) from a Corpus
    • Check Duplicate Documents in a Corpus
    • Trigger a Refresh (Reindex) of a Corpus
    • Get Sitemaps for a Corpus
    • Get Corpora with Refresh (Reindex) Enabled
  • Documents
    • Get a Document
    • Update a Document
    • Delete a Document
    • Annotate a Document
    • Get Conversation Starters for a Document
    • Trigger a Refresh (Reindex) of a Document
    • Retrieve multiple Documents by IDs
  • Organizations
    • Organization Permissions
      • List all permissions on an organization
      • Get user permissions on a specific organization
    • Get all Configurations
    • Get active configuration for an Organization
    • Get the Model Deployment for an Organization
    • Get all Tools in an Organization
    • Disable a Tool for all Agents in an Organization
    • Enable a Tool for all Agents in an Organization
    • Get all API Tool Templates
    • Create a new API Tool Template
    • Create a new API tool
    • Create an attachment tool
    • Create a new RAG tool in an Organization
    • Create a Web Search Tool in an Organization
    • Get all Users in an Organization
    • Create a User in an Organization
    • Get all Configurations of user's Organization
    • Register LLM Configuration
    • Update LLM Configuration
    • Toggle LLM Configuration Availability
    • Delete LLM Configuration
    • Get a specific LLM configuration by ID (admin only)
  • Users
    • Get a User
    • Update a User
    • Delete a User
    • Get Agent Responses of a User
    • Get all User Permissions
    • Get Projects of a User
    • Get all Workflow Tables for a User
    • Get all Workflows for a User
    • Delete multiple Users
    • Get a specific User by user_email
    • Get all Users
    • Get authenticated User
    • Get User Projects
    • Assign a user to multiple permission sets
  • Analytics
    • Get Agent Cost Data
    • Get Agent Document Count Data
    • Get Agent Indexing Mode Data
    • Get Agent Most Active Data
    • Get Agent Query Count Data
    • Get Recent Agent Data
    • Get Agent Summary Statistics
    • Get Agent Token Data
    • Get Agent Vote Data
    • Get Corpus Document Count Data
    • Get Corpus Indexing Mode Data
    • Get Cost Data
    • Get Document Count Data
    • Get Indexing Mode Data
    • Get Project Cost Data
    • Get Project Document Count Data
    • Get Project Indexing Mode Data
    • Get Project Most Active Data
    • Get Project Query Count Data
    • Get Recent Project Data
    • Get Project Summary Statistics
    • Get Project Token Data
    • Get Project Vote Data
    • Get Overall Summary Statistics
    • Get Team Cost Data
    • Get Team Document Count Data
    • Get Team Indexing Mode Data
    • Get Team Most Active Data
    • Get Team Query Count Data
    • Get Recent Team Data
    • Get Team Summary Statistics
    • Get Team Token Data
    • Get Team Vote Data
    • Get Total Entity Counts
    • Get User Cost Data
    • Get User Document Count Data
    • Get User Indexing Mode Data
    • Get User Most Active Data
    • Get User Query Count Data
    • Get Recent User Data
    • Get User Summary Statistics
    • Get User Token Data
    • Get User Vote Data
    • Get Vote Count Data
    • Get Workflow Summary Statistics
    • Get Query Count Data
    • Get Token Data
  • Configurations
    • Update the LLM configuration for an Agent
    • Get OAuth-related Feature Flags
  • Guardrails
    • Apply Guardrails on Input Text
    • Get available guardrail types for agent
    • Enable/disable a guardrail type for agent
    • Get Guardrails
    • Update Guardrails
    • Delete Guardrails
    • Get Guardrails in Organization
    • Create Guardrail in Organization
    • Enable or Disable Guardrail for Organization
  • Feature Flags
    • Get All Feature Flags
    • Get Agent Alias Feature Flag
    • Get Agent Evaluation Feature Flag
    • Get Api Tools Feature Flag
    • Get Caching Feature Flag
    • Get Call Feature Flag
    • Get Chat Agent Creation Feature Flag
    • Get Chat Widget Feature Flag
    • Get dall_e Image Generation Feature Flag
    • Get Developer Portal Feature Flag
    • Get Flush Cache Feature Flag
    • Get Google Drive Connector Feature Flag
    • Get Guardrail Feature Flag
    • Permission Sets Feature Flag
    • Get PII Redaction Feature Flag
    • Get Share Agent Feature Flag
    • Get Sharepoint Legacy Feature Flag
    • Show Quota Limit Feature Flag
    • Get Skills Feature Flag
    • Get Staging Agent Feature Flag
    • Get Workflow Evaluation Feature Flag
    • Get Youtube Index Feature Flag
  • Notifications
    • Get all Notifications
    • Create a new Notification
    • Update Notifications by User ID
    • Get a Notification
    • Update a Notification
    • Delete a Notification
  • Tools
    • Get Tool by ID
    • Update Tool by ID
    • Delete Tool by ID
  • Workflows
    • Evaluation Datasets
      • List Workflow Evaluation Datasets
      • Create Workflow Evaluation Dataset
      • Batch Delete Workflow Evaluation Datasets
      • Get Workflow Evaluation Dataset
      • Update Workflow Evaluation Dataset
      • Delete Workflow Evaluation Dataset
      • Upload Workflow Evaluation Dataset (CSV/Excel)
    • Evaluation Runs
      • List Workflow Evaluation Runs
      • Create Workflow Evaluation Run
      • Batch Delete Workflow Evaluation Runs
      • Get Workflow Evaluation Run
      • Update Workflow Evaluation Run
      • Delete Workflow Evaluation Run
    • Workflow Permissions
      • Get all Permissions for a Workflow
      • Grant permission on a Workflow
      • Update a permission on a Workflow
      • Revoke permission on a Workflow
      • Batch grant permissions on a Workflow
      • Batch revoke permissions on a Workflow
      • Get a user's permissions on a workflow
      • Get a user's permissions across multiple workflows
    • Get all Workflows
    • Stream Workflow Response (SSE)
    • Create a Workflow
    • Get a Workflow
    • Update a Workflow
    • Delete a Workflow
    • Get all Workflow Chat Threads
    • Create a Workflow Chat Thread
    • Get all Workflow Responses
    • Create a Workflow Chat Response
    • Get a Workflow Chat Thread
    • Update a Workflow Chat Thread
    • Delete a Workflow Chat Thread
    • Get all Workflow Chat Responses
    • Delete a Workflow Response
    • Create a Workflow Feedback
    • Retrieve a list of reviews for a given workflow response
    • Create a Workflow Review
    • Get Workflow Responses based on filters
  • Citation
    • Get Citation File Content
  • Sitemaps
    • Get a Sitemap
    • Toggle Sitemap Syncing
    • Delete a Sitemap (cascade)
    • Get documents linked to a Sitemap
  • Google Drive
    • Folder Mappings
      • Get Google Drive Folder Mappings by Corpus ID
  • Skills
    • List all Skills in an Organization
    • Create a new Skill
    • Retrieve a Skill in an Organization
    • Update a Skill
    • Disable a Skill for all Agents in an Organization
    • Update Skill Metadata
    • Enable a Skill for all Agents in an Organization
    • Delete a Skill
    • Get a Skill with Content
    • Get a File from a Skill
  • Permission Sets
    • List org permission sets
    • Create a permission set
    • Retrieve a permission set
    • Update a permission set
    • Delete a permission set
    • List permission set members
    • Assign one or more members to a permission set
    • Remove one or more members from a permission set
  1. Authentication

Authentication and Token Refresh Guide

Refreshing the Access Token#

Ejento AI access tokens are short-lived for security. This guide explains how to obtain tokens through login, how to refresh them, and the flow around it — so you can keep a session authenticated from any client, whether you are building a frontend or a backend integration. The API interaction is identical in both cases; only where you store the tokens differs.
For a complete overview of every authentication option, see the Getting Started with Authentication guide.

The Tokens#

When a user authenticates, you receive two tokens:
access_token — authorizes the authentication service, including the refresh endpoint itself.
ejento_access_token — authorizes your calls to the Ejento AI API (chat, agents, corpora, and so on).
Both tokens are time-limited and will eventually expire. The refresh endpoint lets you exchange your current access_token for a fresh pair of tokens before that happens — without asking the user to log in again.

Prerequisites#

Your Ejento API key.
The Base URL for your Ejento environment.

Obtaining the Tokens (Login)#

Before you can refresh, you need an initial token pair. Ejento AI supports several login methods — see the Getting Started with Authentication guide for the full list. This guide uses Microsoft Azure AD (SSO) login as the example; whichever method you choose, the result is the same: an access_token and an ejento_access_token.
In short: You only call the Azure AD login endpoint once, during initial setup. Store the returned access_token and ejento_access_token — from here on, use the ejento_access_token to call the Ejento API and the access_token to refresh. You do not log in again: instead, call the refresh endpoint at least once every 6 days to obtain a fresh pair before the current tokens expire, and replace your stored tokens with the new ones. This keeps your session alive indefinitely without repeating the login step.

Step 1 — Get the Azure AD token (MSAL) (skip if you already obtain the token your own way)#

The azure_ad_token used below comes from Microsoft's Authentication Library (MSAL). In short: configure MSAL with your Azure AD application, sign the user in, and acquire a token for your scope.
Note: The snippet below is only an example. If you already obtain Azure AD tokens some other way, keep using your existing approach — all Ejento needs is a valid azure_ad_token.
On a backend, use @azure/msal-node instead. See Microsoft's MSAL documentation for full setup.

Step 2 — Exchange it for Ejento tokens#

Exchange the Azure AD token for Ejento tokens in a single request.
Endpoint:
Request headers:
Request body (JSON):
{
  "email": "[email protected]",
  "azure_ad_token": "<azure-ad-token>",
  "full_name": "Jane Doe", // optional
  "auto_create": true, // optional
  "organization_id": "<organization-id>" // optional
}
FieldRequiredDescription
emailYesThe user's email address.
azure_ad_tokenYesThe token issued by Microsoft Azure AD.
full_nameNoUsed when creating a new user.
auto_createNoCreate the user automatically if they do not exist.
organization_idNoThe organization to associate the user with.
Response — 200 OK
{
  "access_token": "<access token>",
  "ejento_access_token": "<ejento access token>",
  "token_type": "bearer"
}
Store the returned access_token and ejento_access_token. As described above, this login step happens only once — from here on you keep your session alive with the refresh endpoint.

The Refresh Endpoint#

Exchange your current tokens for a new pair.
Headers
HeaderValueDescription
AuthorizationBearer {access_token}Your current access_token. This is what the endpoint authenticates.
Ocp-Apim-Subscription-Key{API_KEY}Your API key.
Request body
None. The refresh is driven entirely by the access_token in the Authorization header.
Successful response — 200 OK
{
  "success": true,
  "message": "Token refreshed",
  "data": {
    "access_token": "<new access token>",
    "ejento_access_token": "<new ejento access token>",
    "token_type": "bearer"
  }
}
Replace both of your stored tokens with the new values from data. The old tokens should no longer be used.
Error responses
StatusMeaningWhat to do
401 UnauthorizedThe access_token is invalid or has fully expired.The session cannot be renewed. Send the user back through the login flow.
422 Unprocessable EntityThe request was malformed.Check the Authorization header format and the API key.

When to Refresh#

Refresh on a schedule. Because you log in with Azure AD only once, you keep the session alive by calling the refresh endpoint at least once every 6 days — before the current tokens expire — and storing the new pair each time.

The Flow, Step by Step#

1.
Store the token pair. After the one-time login, keep the access_token and ejento_access_token in secure storage (for example, Azure Key Vault).
2.
Call the API. Send requests with Authorization: Bearer {ejento_access_token} and the Ocp-Apim-Subscription-Key header.
3.
Refresh every 6 days. On a schedule, before the 7-day expiry, call POST /auth-service/api/v2/users/refresh-access-token with Authorization: Bearer {access_token} and the API key.
4.
Store the new tokens. On 200, replace both stored tokens with the new access_token and ejento_access_token from data.
5.
Keep calling the API with the refreshed ejento_access_token. Because you refresh ahead of expiry, requests never fail due to an expired token.
To prevent an endless loop, retry the original request only once after a refresh.

Summary#

Obtain the initial access_token and ejento_access_token through a login endpoint (this guide uses Microsoft Azure AD SSO; see the Getting Started with Authentication guide for other methods).
You log in only once during setup; after that, refresh the tokens at least every 6 days to get a new pair without logging in again.
Authenticate the refresh call with your current access_token; you receive a new access_token and ejento_access_token.
Run only one refresh at a time and let concurrent requests share its result.

Previous
Getting Started with Authentication
Next
Initiate Google SSO Login
Built with