> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anlytic.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange OTP for workspace token

> Exchange a one-time passcode for a signed JWT.

Replace `{kid}` with the workspace key identifier provided for your integration.

Uses **HTTP Basic Auth** — pass `email` as username and the **OTP code** received by email in the password field.

```text
Authorization: Basic <encoded-value>
```

Example with cURL:

```bash
curl --request GET \
  --url https://app.anlytic.com/api/v1/users/token/{kid} \
  --header 'Authorization: Basic <encoded-value>'
```




## OpenAPI

````yaml api-reference/openapi.yaml get /api/v1/users/token/{kid}
openapi: 3.1.0
info:
  title: Anlytic API
  version: '1.0'
  description: >
    The Anlytic REST API. All endpoints are served under `/api/v1/`.


    ## Authentication


    Most endpoints require a **Bearer JWT** obtained via the authentication
    flow:

    1. `GET /api/v1/users/otp` — request a one-time passcode (uses HTTP Basic
    Auth)

    2. `GET /api/v1/users/token/{kid}` — exchange OTP for a workspace JWT.


    Include the JWT in every subsequent request with `Authorization: Bearer
    <token>`.


    Alternatively, use an **API Key** via the same header: `Authorization:
    API-Key <key>`.


    ## Roles & Scopes


    | Scope | Description |

    |---|---|

    | `workspace_viewer` | Read-only access to workspace resources |

    | `workspace_editor` | Create and update resources |

    | `workspace_admin` | Full workspace management including billing |

    | `admin` | System-level operations (Anlytic staff only) |
  contact:
    name: Anlytic Support
    url: https://anlytic.com
servers:
  - url: https://app.anlytic.com
    description: Production
security:
  - bearerAuth: []
  - apiKeyAuth: []
tags:
  - name: Configuration
    description: API configuration and policy endpoints
  - name: Authentication
    description: Login, OTP, token exchange, and MFA flows
  - name: Users
    description: User profile and settings management
  - name: API Keys
    description: Programmatic API key management per user
  - name: MFA
    description: Multi-factor authentication setup and verification
  - name: Workspaces
    description: Workspace lifecycle management
  - name: Workspace Members
    description: Manage users within a workspace
  - name: Teams
    description: Team creation and membership management
  - name: Sources
    description: Database source connections and schema exploration
  - name: Columns
    description: Column metadata and value search
  - name: Connectors
    description: Fivetran sync connector management
  - name: Uploads
    description: File upload ingestion (CSV, JSON, Parquet)
  - name: Webhooks
    description: Inbound webhook endpoints for external data ingestion
  - name: Actions
    description: Custom action definitions triggered from dashboards
  - name: Enrichments
    description: Data enrichment pipeline management
  - name: Dashboards
    description: Dashboard creation and management
  - name: Charts
    description: Chart configuration and data retrieval
  - name: Workbooks
    description: Spreadsheet-style workbook management
  - name: Filters
    description: Reusable data filter management
  - name: Folders
    description: Content organisation into folders
  - name: AI Assistant
    description: AI assistant sessions and message history
  - name: Payments
    description: Stripe billing, subscriptions, and plan management
  - name: Notifications
    description: In-app notification management
  - name: Catalog
    description: Workspace data catalog overview
  - name: Favorites
    description: User-level content favorites
paths:
  /api/v1/users/token/{kid}:
    get:
      tags:
        - Authentication
      summary: Exchange OTP for workspace token
      description: >
        Exchange a one-time passcode for a signed JWT.


        Replace `{kid}` with the workspace key identifier provided for your
        integration.


        Uses **HTTP Basic Auth** — pass `email` as username and the **OTP code**
        received by email in the password field.


        ```text

        Authorization: Basic <encoded-value>

        ```


        Example with cURL:


        ```bash

        curl --request GET \
          --url https://app.anlytic.com/api/v1/users/token/{kid} \
          --header 'Authorization: Basic <encoded-value>'
        ```
      operationId: exchangeOtpForWorkspaceToken
      parameters:
        - name: kid
          in: path
          required: true
          schema:
            type: string
            example: workspace-key-id
          description: Workspace key identifier.
          example: workspace-key-id
      responses:
        '200':
          description: JWT token pair
          content:
            application/json:
              schema:
                type: object
                required:
                  - access_token
                  - refresh_token
                properties:
                  access_token:
                    type: string
                  refresh_token:
                    type: string
                  last_login_at:
                    oneOf:
                      - $ref: '#/components/schemas/Timestamp'
                      - type: 'null'
                  mfa_setup_required:
                    type: boolean
        '401':
          $ref: '#/components/responses/Unauthorized'
      security:
        - basicAuth: []
components:
  schemas:
    Timestamp:
      type: string
      format: date-time
      example: '2024-01-15T10:30:00Z'
    Error:
      type: object
      properties:
        error:
          type: string
          description: Human-readable error message
        code:
          type: string
          description: Machine-readable error code
  responses:
    Unauthorized:
      description: Missing or invalid authentication token
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: Enter `API-Key <key>`.
    basicAuth:
      type: http
      scheme: basic
      description: >
        HTTP Basic Auth. For OTP request: pass `email` as username only
        (password field is ignored).

        For token exchange: pass `email` as username and the OTP code (received
        by email) in the password field (`email:otp_code`).

````