Authentication
PADS4 Foundation uses cookie-based session authentication — not Bearer tokens.1. Log in
Set-Cookie header containing the session cookie. The response body is an array of 16 identity claims (user ID, display name, email, domain, roles, etc.) — it is NOT a token you send back.
2. Use the session cookie
PADS4 REST conventions
PADS4 Foundation uses a non-standard REST pattern that differs from typical CRUD APIs:
Why POST for listing? PADS4 passes filter/pagination parameters in the request body (complex objects with
PageIndex, PageSize, filters, sorts). This avoids the URL length limits and URL-encoding complexity of large filter sets in query strings.

