Skip to content

Authentication ​

A student account uses email and password. Owlflow returns a JWT. Send it on later requests as Authorization: Bearer <token>.

Which partner the account belongs to comes from the request host, and only at signup and login. See How we identify partners. Do not send a domain in the GraphQL input.

Create an account ​

Send an Idempotency-Key header on this call only. scholarships.net sets it to a new UUID for each signup attempt. A retry with the same key returns the original account instead of creating a second one. Owlflow requires the header on the native registration path, and the value must be 128 characters or fewer.

graphql
mutation Signup($input: CreateUserInput!) {
  auth {
    createUser(input: $input) {
      success
      token
      expiresAt
      user {
        id
        email
        firstName
        lastName
      }
      errors {
        code
        field
        message
      }
    }
  }
}

email is required. A successful signup returns a token, so the student is already signed in.

Sign in ​

graphql
mutation Login($input: LoginInput!) {
  auth {
    login(input: $input) {
      token
      expiresAt
      user {
        id
        email
        firstName
        lastName
      }
    }
  }
}

LoginInput is email, password, and optional remember.

Refresh and sign out ​

auth.refreshToken returns a new token and expiresAt. A recently expired token still refreshes inside the grace window.

auth.logout revokes the current token and returns a boolean.

Who is signed in ​

graphql
query CurrentUser {
  me {
    id
    email
    firstName
    lastName
  }
}

Owlflow partner API