Appearance
Authentication
A student account uses email and password. Owlflow returns a JWT. Send it on later requests as Authorization: Bearer <token>.
Which partner the account belongs to comes from the request host, and only at signup and login. See How we identify partners. Do not send a domain in the GraphQL input.
Create an account
Send an Idempotency-Key header on this call only. scholarships.net sets it to a new UUID for each signup attempt. A retry with the same key returns the original account instead of creating a second one. Owlflow requires the header on the native registration path, and the value must be 128 characters or fewer.
graphql
mutation Signup($input: CreateUserInput!) {
auth {
createUser(input: $input) {
success
token
expiresAt
user {
id
email
firstName
lastName
}
errors {
code
field
message
}
}
}
}email is required. A successful signup returns a token, so the student is already signed in.
Sign in
graphql
mutation Login($input: LoginInput!) {
auth {
login(input: $input) {
token
expiresAt
user {
id
email
firstName
lastName
}
}
}
}LoginInput is email, password, and optional remember.
Refresh and sign out
auth.refreshToken returns a new token and expiresAt. A recently expired token still refreshes inside the grace window.
auth.logout revokes the current token and returns a boolean.
Who is signed in
graphql
query CurrentUser {
me {
id
email
firstName
lastName
}
}