Documentation / API Authentication / Authentication Errors

Authentication Errors

Authentication Errors for PanelConfig API consumers and operators.

Authentication failures should be handled as hard stops by API clients. A 401 means the client cannot prove its identity; a 403 means the user is authenticated but not allowed to access the requested resource.

Procedure

  1. Generate or identify the token in PCAdmin.
  2. Send a validation request to /api/v1/me.php.
  3. Confirm that the JSON envelope contains success: true.
  4. Move the token into the final secret storage location.
  5. Review request logs after the integration starts using the API.

Example

curl -i https://panel.example.com/api/v1/me.php \
  -H "Authorization: Bearer pc_YOUR_TOKEN" \
  -H "Accept: application/json"

Troubleshooting

  • Check that the web server forwards the Authorization header to PHP.
  • Make sure the token starts with the copied pc_ value and has not been cut off.
  • Confirm the token has not expired.
  • Confirm the user attached to the token is still active.

Audit Logging

Token creation calls the audit helper. Authenticated API requests update last_used_at and insert request records into api_requests when the table exists.

← Revoking Tokens Validating Authentication with Curl →