Skip to main content

Authentication

PADS4 Foundation uses cookie-based session authentication — not Bearer tokens.

1. Log in

Response body:
The server sets a Set-Cookie header containing the session cookie. The response body is an array of 16 identity claims (user ID, display name, email, domain, roles, etc.) — it is NOT a token you send back.
In Postman: After running the Logon request, Postman stores the session cookie and includes it automatically in subsequent requests to the same domain. In fetch / browser:

PADS4 REST conventions

PADS4 Foundation uses a non-standard REST pattern that differs from typical CRUD APIs: Why POST for listing? PADS4 passes filter/pagination parameters in the request body (complex objects with PageIndex, PageSize, filters, sorts). This avoids the URL length limits and URL-encoding complexity of large filter sets in query strings.

List example

Create example


Standard response envelope

All PADS4 API responses wrap their payload in a standard envelope:

Common infrastructure endpoints

Every PADS4 microservice exposes these endpoints regardless of its domain: