sondahub / Auth test endpoints
Auth test endpoints
Every common way an API asks who you are, checked for real — so a client’s auth can be proven before it meets a server that matters. Public credentials, honest failures: 401 with the challenge, 403 with what the server computed.
One endpoint per scheme
Try each one
curl -u sonda:probe https://api.sondahub.com/v1/utils/auth/basic
curl -i -u sonda:nope https://api.sondahub.com/v1/utils/auth/basic
curl --digest -u sonda:probe "https://api.sondahub.com/v1/utils/auth/digest?algorithm=SHA-256"
curl -H "X-API-Key: sonda-probe-key" https://api.sondahub.com/v1/utils/auth/apikey
curl "https://api.sondahub.com/v1/utils/auth/apikey?api_key=sonda-probe-key"
curl -H "Authorization: Bearer anything" https://api.sondahub.com/v1/utils/auth/bearer
curl --aws-sigv4 "aws:amz:us-east-1:execute-api" \ --user "AKIASONDAHUB000001:probe-secret" \ https://api.sondahub.com/v1/utils/auth/sigv4
JWT: mint, verify, use
Mint, decode, verify and use tokens. HS256 secret probe-secret; RS256 keys published (the private one too — it is a playground).
curl "https://api.sondahub.com/v1/utils/jwt/issue?sub=alice&role=admin"
curl -H "Authorization: Bearer TOKEN" https://api.sondahub.com/v1/utils/jwt/protected
For full OAuth 2.0 and OpenID Connect flows, see the OAuth 2.0 test server.
Questions
What are the credentials?
User sonda / probe for Basic and Digest (or any pair you put in the path), API key sonda-probe-key, JWT secret probe-secret, AWS key AKIASONDAHUB000001 / probe-secret in us-east-1 for execute-api. All public on purpose.
How do I debug an AWS Signature V4 that fails?
A signature that does not match answers 403 with the canonical request and the string-to-sign the server built from your request. Put them next to the ones your signer logged; the first line that differs is the bug.
Which Digest variants are supported?
RFC 7616: ?algorithm=MD5, MD5-sess, SHA-256 or SHA-256-sess, and ?qop=auth or auth-int. A failed check says which part did not match.
What does a failed login look like?
401 with a WWW-Authenticate challenge, as a real server sends — except /auth/hidden-basic, which answers 404 as if the route did not exist, for clients that must cope with servers that hide.