aYOUne
translate
Not in your language

This page is not yet available in en. You're reading the de version.

CORS & Auth

Wenn du aus einer Browser-App heraus die aYOUne-API ansprichst, brauchst du sowohl korrektes CORS-Setup als auch ein durchdachtes Token-Lifecycle-Modell. Beides ist hier zusammengefasst.

CORS-Verhalten

Per Default akzeptieren die Module-APIs nur Origins, die in der Customer-Konfiguration unter aYOUneCustomers.allowedOrigins[] registriert sind. Trag deinen Frontend-Origin dort ein:

ay update ayounecustomers <customerId> \
  --set allowedOrigins='["https://app.firma.tld","https://staging.firma.tld"]'

Wildcards (*.firma.tld) sind unterstützt. Auf Self-Hosted-Instanzen kannst du via Umgebungsvariable CORS_ORIGIN_OVERRIDE zusätzlich global öffnen — siehe Environment Variables.

JWT-Lifecycle

aYOUne arbeitet mit zwei Tokens:

Token TTL Zweck
Access-Token 15 min Bei jedem API-Call mitgeschickt
Refresh-Token 30 Tage Holt neue Access-Tokens

Access-Token erneuern

Erkennst du an einem Response mit 401, dass der Access-Token abgelaufen ist, hol dir den neuen via:

curl -X POST https://auth.ayoune.app/refresh \
  -H "Content-Type: application/json" \
  -d '{"refreshToken":"<refresh>"}'

Antwort: neues payload.token + neuer payload.refreshToken (Token-Rotation).

Logout & Revocation

curl -X POST https://auth.ayoune.app/logout \
  -H "Authorization: Bearer $TOKEN"

Logout setzt den Refresh-Token in die Blacklist. Access-Tokens laufen ohnehin in 15 min aus — wer höhere Sicherheit braucht, kann sie via ay storage set token schon vorher invalidieren.

Service-Token (Server-zu-Server)

Für Backend-Integrationen (z.B. dein ERP holt nachts Stündliche), nutze Service-Tokens:

ay create credentials "ERP-Sync" \
  --type service-account \
  --rights '["consumers.view","consumers.create"]'

Service-Tokens haben kein Refresh — du rotierst sie aktiv via ay credentials refresh <id>. Sie sind im Audit-Log als Aktor service:<name> zu erkennen.

SameSite & Cookies

aYOUne speichert Tokens nicht in Cookies — die Plattform vertraut auf Authorization-Header. Wenn du in einer SPA arbeitest, leg den Access-Token im Speicher (z.B. sessionStorage) ab, nie im localStorage. Refresh-Tokens gehören ausschließlich in HttpOnly + Secure + SameSite=Strict Cookies, falls du sie browserseitig hältst.

Multi-Tenant Customer-Switch

Ein User kann mehreren Customers angehören. Wechsle innerhalb derselben JWT-Session via:

curl -X GET "https://auth.ayoune.app/changecustomer?customerId=<id>" \
  -H "Authorization: Bearer $TOKEN"

Antwort: ein neues JWT mit dem gewählten Customer-Scope. Alte Tokens bleiben gültig, zeigen aber auf den vorherigen Customer.

Siehe auch: Audit-Trail.

Work with this page

Ready-made instructions for your AI tool. Copy, paste, go — the AI fetches the content itself via the address in the text.

Summarise the steps for me The essentials, in the right order.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/developer-portal/cors-and-auth.md
The complete collection: https://ayoune.com/en/docs/developer-portal.md

Summarise the content for me.

- First, in two sentences: what is this about?
- Then the steps in the order I need to take them.
- One line per step, in plain language.
- At the end: what I should have ready beforehand.

Leave out nothing I need in order to actually finish.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
Help me set this up Step by step, asking me as you go.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/developer-portal/cors-and-auth.md
The complete collection: https://ayoune.com/en/docs/developer-portal.md

Walk me through the setup step by step.

- First tell me what I need to have ready (access, data, time).
- Then take me through ONE step at a time. Wait for my "next".
- For each step, say how I can tell that it worked.
- If something goes wrong, ask me for the exact message instead of guessing.

If the instructions leave a point open, tell me so rather than inventing it.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
Help me with a problem Narrow down the cause instead of guessing.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/developer-portal/cors-and-auth.md
The complete collection: https://ayoune.com/en/docs/developer-portal.md

Help me narrow down a problem.

- First ask me what I observe and what I expected instead.
- From that, derive the most likely causes consistent with this source.
- For each cause, give me ONE test that confirms or rules it out.
- Order them so the cheapest test comes first.

Do not guess. If the source does not cover the problem, tell me where I should
look next.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
Explain it in plain words No jargon, from the ground up.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/developer-portal/cors-and-auth.md
The complete collection: https://ayoune.com/en/docs/developer-portal.md

Explain the content so that someone without prior knowledge understands it.

- Start with the purpose: why does this exist at all?
- Explain technical terms in half a sentence on first use.
- One everyday comparison where it genuinely holds — none where it limps.
- At the end: the three things worth remembering.

Do not shorten by dropping conditions. A simplification that hides a
prerequisite is a false statement.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
A checklist to tick off To follow along while you do it.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/developer-portal/cors-and-auth.md
The complete collection: https://ayoune.com/en/docs/developer-portal.md

Turn this into a **tick-off checklist** for practical use.

- Exactly one action per item, in the imperative.
- Order it so that no item depends on a later prerequisite.
- Prerequisites and pitfalls as indented sub-items.
- End with an acceptance step: how do I know everything is right?
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.
Build it into my project Concrete code for my use case.
Read the following documentation by tolinax UG and work with it.

This page: https://ayoune.com/en/docs/developer-portal/cors-and-auth.md
The complete collection: https://ayoune.com/en/docs/developer-portal.md

Help me build this into my project.

- First ask me about language, environment and what I am trying to achieve.
- Then give a minimal, runnable example — no ellipses standing in for code.
- Name the error cases I must handle and how they surface.
- State the limits: timeouts, quotas, permissions.

Use only what the source actually describes. Do not invent fields, parameters
or endpoints — an invented call costs me more time than it saves.
A note on sources:
- Every page of this documentation is available as Markdown (the same address with `.md`).
- A machine-readable overview of all public content is at `/llms.txt`.
- If you have access to the aYOUne MCP server, you can work against live data
  instead of this snapshot. If not, ignore this point.

Was this article helpful?

👎 No (0)
Leave a comment