Skip to main content

Login / Authentication

The Solinteg Cloud Open API uses Token authentication: first call the login API to exchange your account and password for a token, then include the token field in the Header of every business request.

Authentication Flow​

┌──────────────┐ 1. Login (account + password) ┌─────────────────────────┐
│ │ ───────────────────────▶ │ │
│ Your App │ │ Solinteg Cloud Open API │
│ │ ◀─────────────────────── │ │
└──────────────┘ 2. Returns token (60 min) └─────────────────────────┘
│
│ 3. Business request (token in Header)
▼
Call business APIs normally; log in again to get a new token after it expires
note

Note: it is a custom token request header, not the standard Authorization: Bearer header.

Obtaining a Token​

Call the login API POST /loginv2/auth, which is the only API on the site that does not require authentication:

curl -L 'https://lb.solinteg-cloud.com/openapi/v2/loginv2/auth' \
-H 'Content-Type: application/json' \
-H 'Accept: application/json' \
--data-raw '{
"authAccount": "user@example.com",
"authPassword": "123456"
}'

The body in the response is the token (JWT format):

{
"errorCode": 0,
"info": null,
"successful": true,
"body": "eyJhbGciOiJIUzI1NiJ9.eyJpYXQiOjE3Nz..."
}

Carrying the Token​

All subsequent business APIs require the token in the request header:

token: YOUR_TOKEN

Example (query device status):

curl -L 'https://lb.solinteg-cloud.com/openapi/v2/wrapper/device/getDeviceStatus?deviceSn=A11250010094305B' \
-H 'Accept: application/json' \
-H 'token: <token>'

Token Validity Period​

The token has a validity period (60 minutes). After it expires, all business APIs return an authentication failure error. In this case, call the login API again to obtain a new token.

tip

Recommended integration strategy

  • Record the token acquisition time and refresh it proactively before expiration (e.g., refresh every 55 minutes)
  • When receiving an authentication failure error, log in again first and then retry the original request
  • Avoid calling the login API before every request; note that the login API also has a QPS limit

Code Examples​

JavaScript (Fetch)​

const baseUrl = "https://lb.solinteg-cloud.com/openapi/v2";

// 1. Log in to get the token
const loginRes = await fetch(`${baseUrl}/loginv2/auth`, {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
authAccount: "user@example.com",
authPassword: "your_password",
}),
});
const loginData = await loginRes.json();
const token = loginData.body;

// 2. Call a business API with the token
const res = await fetch(`${baseUrl}/wrapper/device/getDeviceStatus?deviceSn=A11250010094305B`, {
headers: {
Accept: "application/json",
token: token,
},
});
const data = await res.json();

Python (Requests)​

import requests

base_url = 'https://lb.solinteg-cloud.com/openapi/v2'

# 1. Log in to get the token
login_res = requests.post(
f'{base_url}/loginv2/auth',
json={
'authAccount': 'user@example.com',
'authPassword': 'your_password'
}
)
token = login_res.json()['body']

# 2. Call a business API with the token
res = requests.get(
f'{base_url}/wrapper/device/getDeviceStatus',
params={'deviceSn': 'A11250010094305B'},
headers={'token': token}
)
print(res.json())

Node.js (Axios)​

const axios = require("axios");

const client = axios.create({
baseURL: "https://lb.solinteg-cloud.com/openapi/v2",
headers: { Accept: "application/json" },
});

let token = null;

// Log in to get the token
async function login() {
const res = await client.post("/loginv2/auth", {
authAccount: "user@example.com",
authPassword: "your_password",
});
token = res.data.body;
}

// Attach the token automatically via a request interceptor
client.interceptors.request.use((config) => {
if (token) config.headers["token"] = token;
return config;
});

await login();
const res = await client.get("/wrapper/device/getDeviceStatus", {
params: { deviceSn: "A11250010094305B" },
});

Authentication Errors​

All APIs follow a unified response structure (errorCode / info / body / successful). When authentication fails, successful is false:

Login Failed - User Does Not Exist​

{
"errorCode": 1,
"info": {
"code": "user not exist",
"description": "user not exist"
},
"body": null,
"successful": false
}

Login Failed - Wrong Password​

{
"errorCode": 1,
"info": {
"code": "password error",
"description": "password error"
},
"body": null,
"successful": false
}

Troubleshooting Authentication Failures on Business APIs​

When you receive authentication-related errors, check:

  • Whether the token field is included in the request headers
  • Whether the token has expired; if so, log in again to obtain a new one
  • Whether you are using the environment address that matches your account

Security Best Practices​

  • Do not hard-code your account, password, or token in your code; manage them with environment variables
  • Never expose your account and password on the client side (browser or app); the login action should be performed by your server

Next Steps​

  • Read Quick Start to make your first API call
  • Browse the API list to learn about all API capabilities