---
notionId: "cba13bdf092a45dc87c908ccdb2bbac8"
product: "developer"
cluster: "apis"
intent: "developer.api-authentication"
docSlug: "api-authentication"
task: "Authentication in the API"
title: "Authentication in the API | VirtualPBX"
meta_description: "The Dash API requires an authentication token on each request. A user auth call turns a hashed username and password, plus the account name, into that token. A"
answer: "The Dash API requires an authentication token on each request. A user auth call turns a hashed username and password, plus the account name, into that token. A server should call api_auth with the account API key instead of a person's password. Reuse the token across a series of requests. It expires after a period of inactivity, so create a new one when the API rejects the old token."
audience: "user"
updated: "2023-09-07"
legacy: ["authentication"]
headings: [{"depth":2,"text":"About Authentication","id":"about-authentication"},{"depth":3,"text":"Creating User Auth Token","id":"creating-user-auth-token"},{"depth":3,"text":"API","id":"api"},{"depth":3,"text":"Payload","id":"payload"},{"depth":3,"text":"Hash the user credentials","id":"hash-the-user-credentials"},{"depth":3,"text":"Request response","id":"request-response"},{"depth":3,"text":"CURL Example","id":"curl-example"}]
lint: []
---

## About Authentication

The Dash API requires you to provide an authentication token with each request.

Using your username and password, along with an account company, you may issue an API call to `user_auth` to generate an authentication token.

Using your account's API token you may issue an API call to `api_auth` to generate an authentication token. If you're building server applications, this is the best way to authenticate your application.

This is the same as authenticating as a user, except you supplying the API key as data.

Once an authentication token is generated, it may be used for subsequent API calls. The Token will expire after a period of inactivity. You may reuse the same token for a series of API requests.

### Creating User Auth Token

When creating an Authentication Token, you must hash the password prior to submitting the `user_auth` request.

### API

Method: PUT

<pre tabindex="0"><code class="language-javascript">https://public-api.virtualpbx.com:8443/v2/user_auth</code></pre>

### Payload

<pre tabindex="0"><code class="language-javascript">{
  &quot;data&quot;: {
    &quot;credentials&quot;: &quot;{{password_hash}}&quot;,
    &quot;account_name&quot;: &quot;{{account_name}}&quot;
  }
}</code></pre>

### Hash the user credentials

On Unix-like systems using Shell:

<pre tabindex="0"><code>PASSWORD=`echo -n username:password | md5sum | awk '{print $1}'`</code></pre>

On Windows using PowerShell:

<pre tabindex="0"><code class="language-powershell">[BitConverter]::ToString((New-Object System.Security.Cryptography.MD5CryptoServiceProvider).ComputeHash([System.Text.Encoding]::UTF8.GetBytes(&quot;username:password&quot;))).Replace('-', '').ToLower()</code></pre>


The following request will create an authentication token. The string in `auth_token` field contains the authentication token.

### Request response

JSON

<pre tabindex="0"><code>{
    &quot;auth_token&quot;: &quot;{AUTH_TOKEN}&quot;,
    &quot;data&quot;: {
        &quot;account_id&quot;: &quot;{ACCOUNT_ID}&quot;,
        &quot;apps&quot;: [],
        &quot;is_reseller&quot;: true,
        &quot;language&quot;: &quot;en-US&quot;,
        &quot;owner_id&quot;: &quot;{OWNER_ID}&quot;,
        &quot;reseller_id&quot;: &quot;{RESELLER_ID}&quot;
    },
    &quot;request_id&quot;: &quot;{REQUEST_ID}&quot;,
    &quot;revision&quot;: &quot;{REVISION}&quot;,
    &quot;status&quot;: &quot;success&quot;
}</code></pre>

### CURL Example

<pre tabindex="0"><code class="language-javascript">curl --location --request PUT 'https://public-api.virtualpbx.com:8443/v2/user_auth' \
--header 'Content-Type: application/json' \
--data-raw '{
  &quot;data&quot;: {
    &quot;credentials&quot;: &quot;{{password_hash}}&quot;,
    &quot;account_name&quot;: &quot;{{account_name}}&quot;
  }
}'</code></pre>
