sondahub

sondahub / Auth test endpoints

Auth test endpoints

Every common way an API asks who you are, checked for real — so a client’s auth can be proven before it meets a server that matters. Public credentials, honest failures: 401 with the challenge, 403 with what the server computed.

One endpoint per scheme

GET/v1/utils/auth/basicHTTP Basic with sonda / probe. /auth/basic/{user}/{pass} takes any pair you name. Wrong or missing answers 401 with WWW-Authenticate.
GET/v1/utils/auth/hidden-basic/{user}/{pass}Basic, but a failure answers 404 as if the route did not exist.
GET/v1/utils/auth/bearerAny non-empty bearer token passes. /auth/bearer/{token} wants exactly that token.
GET/v1/utils/auth/apikeyX-API-Key: sonda-probe-key (or ?api_key=, or Authorization: ApiKey …). /auth/apikey/{key} wants that key instead.
GET/v1/utils/auth/digestHTTP Digest (RFC 7616) with sonda / probe: ?algorithm=MD5|MD5-sess|SHA-256|SHA-256-sess and ?qop=auth|auth-int choose the challenge; /auth/digest/{user}/{pass} takes any pair. A failed check says which part did not match.
ANY/v1/utils/auth/sigv4AWS Signature Version 4, verified: access key AKIASONDAHUB000001, secret probe-secret, region us-east-1, service execute-api. A mismatch answers 403 with the canonical request and string-to-sign the server built, to compare with yours.

Try each one

Basic
curl -u sonda:probe https://api.sondahub.com/v1/utils/auth/basic
Basic, wrong password — 401 with a challenge
curl -i -u sonda:nope https://api.sondahub.com/v1/utils/auth/basic
Digest, SHA-256
curl --digest -u sonda:probe "https://api.sondahub.com/v1/utils/auth/digest?algorithm=SHA-256"
API key in a header
curl -H "X-API-Key: sonda-probe-key" https://api.sondahub.com/v1/utils/auth/apikey
API key in the query
curl "https://api.sondahub.com/v1/utils/auth/apikey?api_key=sonda-probe-key"
Bearer, any token
curl -H "Authorization: Bearer anything" https://api.sondahub.com/v1/utils/auth/bearer
AWS SigV4 (curl 7.75+)
curl --aws-sigv4 "aws:amz:us-east-1:execute-api" \
  --user "AKIASONDAHUB000001:probe-secret" \
  https://api.sondahub.com/v1/utils/auth/sigv4

JWT: mint, verify, use

Mint, decode, verify and use tokens. HS256 secret probe-secret; RS256 keys published (the private one too — it is a playground).

GET/v1/utils/jwt/issue?sub=alice&role=admin&alg=HS256&expires_in=3600A token with the query parameters as claims. POST {"alg","expires_in","claims":{…}} for anything richer.
POST/v1/utils/jwt/verify{"token": …} (or ?token=, or a Bearer header): valid or not, why, and the claims.
GET/v1/utils/jwt/decode?token=…Header and payload, nothing checked.
GET/v1/utils/jwt/protectedNeeds a valid Bearer JWT signed with either key. Sign your own and it passes.
GET/v1/utils/jwt/keysThe HS256 secret and the RS256 private JWK.
Mint a token
curl "https://api.sondahub.com/v1/utils/jwt/issue?sub=alice&role=admin"
Use it
curl -H "Authorization: Bearer TOKEN" https://api.sondahub.com/v1/utils/jwt/protected

For full OAuth 2.0 and OpenID Connect flows, see the OAuth 2.0 test server.

Questions

What are the credentials?

User sonda / probe for Basic and Digest (or any pair you put in the path), API key sonda-probe-key, JWT secret probe-secret, AWS key AKIASONDAHUB000001 / probe-secret in us-east-1 for execute-api. All public on purpose.

How do I debug an AWS Signature V4 that fails?

A signature that does not match answers 403 with the canonical request and the string-to-sign the server built from your request. Put them next to the ones your signer logged; the first line that differs is the bug.

Which Digest variants are supported?

RFC 7616: ?algorithm=MD5, MD5-sess, SHA-256 or SHA-256-sess, and ?qop=auth or auth-int. A failed check says which part did not match.

What does a failed login look like?

401 with a WWW-Authenticate challenge, as a real server sends — except /auth/hidden-basic, which answers 404 as if the route did not exist, for clients that must cope with servers that hide.