UnityAuth API · v1

One identity for every UNX app.

UnityAuth is the sign-in, session and access layer behind auth.unx.ng. Add accounts, verified email, roles and tenants to your app without building any of it.

Base URL
auth.unx.ng
Sessions
HttpOnly cookies
Default tenant
UnityHUB · unityx
Quickstart · curl
# 1. Create an account (a 6-digit code is emailed)
curl -X POST https://auth.unx.ng/v1/auth/sign-up/email \
  -H "Origin: https://your.app" -H "Content-Type: application/json" \
  -d '{"name":"Ada Obi","email":"ada@example.com","password":"at-least-8-chars"}'

# 2. Verify the email: this also signs the user in (cookie saved to jar.txt)
curl -X POST https://auth.unx.ng/v1/auth/email-otp/verify-email -c jar.txt \
  -H "Origin: https://your.app" -H "Content-Type: application/json" \
  -d '{"email":"ada@example.com","otp":"123456"}'

# 3. Who am I, and what may I do?
curl https://auth.unx.ng/v1/me/permissions -b jar.txt

What you get

The whole identity layer, already built.

Every way to sign in

Email and password, username, passwordless email codes, and Google, Microsoft, Apple, GitHub, Facebook, LinkedIn or X. One user either way.

Verified by default

Credential sign-ups confirm their email with a 6-digit code before a password works. Codes are hashed, short-lived and rate-limited.

Roles and permissions

user, support, admin and super-admin, expressed as resource:action keys your app can check with one call.

Tenants

Organisations with owners and members. Every account belongs to UnityHUB (tid unityx), the default tenant.

Sessions and devices

HttpOnly cookie sessions with device, IP and approximate location. Users can sign any device out.

Audit everything

Sign-ins, resets, role changes and refused admin actions land in an append-only audit log.

How it fits

Your app never touches a token.

Users sign in on auth.unx.ng. Your app reads the session from a cookie on the same site, then asks UnityAuth what the user may do. Identity, sessions and tenants live in UnityAuth; your app keeps its own data, linked by immutable ids such as usr_… and org_….

  1. Send users to sign in at auth.unx.ng, or build your own form on the same endpoints.
  2. Read the session with GET /v1/auth/get-session.
  3. Check access with GET /v1/me/permissions and /v1/me/tenants.
Read the session · JavaScript
// Same-origin fetch from your app's BFF or browser code
const res = await fetch("/v1/auth/get-session", { credentials: "include" });
const session = await res.json(); // { user, session } or null

if (!session) location.assign("https://auth.unx.ng/");

Start with the docs.

Every endpoint, request body and error, on one page.

Open documentation