Get admins list
Open Loyalty has the JWT authorization. To learn what a JSON Web Token is and how it works, check out Introduction to JSON Web Tokens https://jwt.io/introduction/
Obtain an access token
Send a request with the parameters username and password
Definition
POST /api/admin/login_check Go to definition
POST /api/{storeCode}/member/login_check Go to definition
Example
curl {HOST}/api/admin/login_check
-H 'Content-Type: application/json;charset=UTF-8'
-H 'Accept: application/json, text/plain, */*'
--data-binary '{"username":"admin","password":"password"}'
Example Response
{
"token":"eyJhbGciOiJSUzI1NiIsInR5cCI6...",
"refresh_token":"0558f8bb29948c4e54c443f..."
}
Using JSON Web Token
Add authorization header to each request
Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6...
You can now access any API method you want under the /api prefix.
Example
curl {HOST}/api/{storeCode}/analytics/members
-H 'Accept: application/json'
-H 'Content-type: application/x-www-form-urlencoded'
-H 'Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6...'
Refresh JSON Web Token
You can refresh token using refresh_token that was given during login.
There are two endpoints
To refresh admin token POST /api/token/refresh Go to definition
To refresh member token POST /api/{storeCode}/token/refresh Go to definition
use createdAt instead
Number of page with results, starts from 1
1Example: 1Items on one page
10Example: 25Bad request.
Forbidden.
GET /api/admin HTTP/1.1
Host: openloyalty.localhost
Authorization: Bearer YOUR_SECRET_TOKEN
Accept: */*
{
"items": [
{
"canChangePassword": false,
"id": "123e4567-e89b-12d3-a456-426614174000",
"username": "text",
"isActive": true,
"createdAt": "2026-01-01T00:00:00.000Z",
"roles": [
{
"role": "text",
"stores": [
{}
],
"id": 1,
"name": "text",
"master": true,
"default": true,
"permissions": [
{}
]
}
],
"email": "text",
"phone": "text",
"settings": {
"notificationsEnabled": "text"
},
"firstName": "text",
"lastName": "text",
"external": true,
"apiKey": "text",
"dtype": "text",
"remoteAuth": [
{}
],
"ignoreAudit": true
}
]
}Last updated
Was this helpful?

