Developers
Getting started

Authentication

Personal access tokens and the one-hour JWT from POST /auth/jwt/.

The public API authenticates with a token in the Authorization header.

Authorization: Token <your_token_here>

The same header shape is used for a personal access token and for the JWT returned by POST /auth/jwt/.

Personal access token

Create and revoke tokens in the web app:

The token is user-specific. Actions taken with it are attributed to the user who created it. Keep it secret. If it leaks, revoke it in those settings. A testing token does not work on https://api.nocfo.io, and a production token does not work on https://api-tst.nocfo.io.

JWT

POST /auth/jwt/ returns a JWT that lasts one hour. Send your personal access token to obtain it, then send the JWT with the same Authorization: Token header.

The operation is Get JWT token. The body may include:

  • business_slug — when set, the token is only valid for that business, and the request path must use that slug.
  • selected_business_slugs — restricts a token that has no business_slug to those businesses.

A selection that resolves to no accessible business is rejected. Read the reference page for the response fields before you store the token.

What this page does not cover

Signing users in with your own application uses an IDP client. Request it from dev@nocfo.io, then follow Sign users in. The login response calls the access token a Bearer token. Send it with the header on this page anyway.

MCP clients authenticate in the browser against https://mcp.nocfo.io. That flow is Connect an AI application. Do not paste an MCP token into Authorization for api.nocfo.io, and do not paste a personal access token into an MCP client configuration.

On this page