Sign-in, accounts, security, and licensing APIs
This layer establishes who is calling, what they may do, and which license limits apply. Interactive users sign in; long-running integrations should use a dedicated least-privilege API token.
This page covers 35 operations. Each row states the endpoint, purpose, timing, completion check, and caller identity. Use the matching OpenAPI file for exact field schemas.
Business APIs may be called by the WebUI or an authorized integration. Administrator APIs require an admin session. Internal APIs and callbacks are only for trusted product components.
API tokens
| Endpoint |
Plain meaning |
When to use it |
How to confirm |
Audience / permission |
Main input |
GET /api/v2/security/api-tokens |
Read security / api tokens. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Administrator API<br>security.tokens.view |
No business input |
POST /api/v2/security/api-tokens |
Create or run security / api tokens. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.tokens.manage |
CreateApiTokenRequest |
DELETE /api/v2/security/api-tokens/{tokenId} |
Delete security / api tokens / the selected tokenId. |
Use it only after the user has reviewed and confirmed the affected data. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.tokens.manage |
tokenId (required) |
PUT /api/v2/security/api-tokens/{tokenId} |
Update security / api tokens / the selected tokenId. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.tokens.manage |
tokenId (required), UpdateApiTokenRequest |
POST /api/v2/security/api-tokens/{tokenId}/reveal |
Create or run security / api tokens / the selected tokenId / reveal. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.tokens.manage |
tokenId (required) |
POST /api/v2/security/api-tokens/{tokenId}/rotate |
Create or run security / api tokens / the selected tokenId / rotate. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.tokens.manage |
tokenId (required) |
Security audit
| Endpoint |
Plain meaning |
When to use it |
How to confirm |
Audience / permission |
Main input |
GET /api/v2/security/audit |
Read security / audit. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Administrator API<br>security.audit.view |
page, pageSize, eventType, outcome, before |
日志与安全
| Endpoint |
Plain meaning |
When to use it |
How to confirm |
Audience / permission |
Main input |
GET /api/v2/security/permissions |
Read security / permissions. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Administrator API<br>authenticated |
No business input |
DELETE /api/v2/security/rtsp-auth |
Delete security / rtsp auth. |
Use it only after the user has reviewed and confirmed the affected data. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.rtsp.manage |
mediaServerId, username |
GET /api/v2/security/rtsp-auth |
Read security / rtsp auth. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Administrator API<br>security.rtsp.view |
mediaServerId, username |
POST /api/v2/security/rtsp-auth |
Create or run security / rtsp auth. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.rtsp.manage |
SaveRtspAuthCredentialRequest |
POST /api/v2/security/rtsp-auth/test |
Create or run security / rtsp auth / test. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.rtsp.manage |
TestRtspAuthCredentialRequest |
Roles and permissions
| Endpoint |
Plain meaning |
When to use it |
How to confirm |
Audience / permission |
Main input |
GET /api/v2/security/roles |
Read security / roles. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Administrator API<br>security.roles.view |
No business input |
POST /api/v2/security/roles |
Create or run security / roles. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.roles.manage |
SaveRoleRequest |
DELETE /api/v2/security/roles/{roleId} |
Delete security / roles / the selected roleId. |
Use it only after the user has reviewed and confirmed the affected data. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.roles.manage |
roleId (required) |
PUT /api/v2/security/roles/{roleId} |
Update security / roles / the selected roleId. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.roles.manage |
roleId (required), SaveRoleRequest |
Users
| Endpoint |
Plain meaning |
When to use it |
How to confirm |
Audience / permission |
Main input |
GET /api/v2/security/users |
Read security / users. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Administrator API<br>security.users.view |
No business input |
POST /api/v2/security/users |
Create or run security / users. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.users.manage |
CreateUserRequest |
DELETE /api/v2/security/users/{userId} |
Delete security / users / the selected userId. |
Use it only after the user has reviewed and confirmed the affected data. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.users.manage |
userId (required) |
PUT /api/v2/security/users/{userId} |
Update security / users / the selected userId. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.users.manage |
userId (required), UpdateUserRequest |
POST /api/v2/security/users/{userId}/password |
Create or run security / users / the selected userId / password. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.users.manage |
userId (required), ChangePasswordRequest |
POST /api/v2/security/users/{userId}/sessions/revoke |
Create or run security / users / the selected userId / sessions / revoke. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Administrator API<br>security.users.manage |
userId (required) |
Sign-in and sessions
| Endpoint |
Plain meaning |
When to use it |
How to confirm |
Audience / permission |
Main input |
POST /api/v2/auth/bootstrap |
Create or run auth / bootstrap. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
First-time setup only<br>专用流程 |
BootstrapAdminRequest |
GET /api/v2/auth/bootstrap-status |
Read auth / bootstrap status. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Public entry<br>专用流程 |
No business input |
GET /api/v2/auth/captcha/{id} |
Read auth / captcha / the selected id. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Public entry<br>专用流程 |
id (required) |
POST /api/v2/auth/captcha/{id}/refresh |
Create or run auth / captcha / the selected id / refresh. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Public entry<br>专用流程 |
id (required) |
POST /api/v2/auth/change-password |
Create or run auth / change password. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Business API<br>authenticated |
ChangePasswordRequest |
POST /api/v2/auth/login |
Create or run auth / login. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Public entry<br>专用流程 |
LoginRequest |
POST /api/v2/auth/logout |
Create or run auth / logout. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Business API<br>authenticated |
No business input |
GET /api/v2/auth/me |
Read auth / me. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Business API<br>authenticated |
No business input |
POST /api/v2/auth/refresh |
Create or run auth / refresh. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Public entry<br>专用流程 |
No business input |
Product licensing
| Endpoint |
Plain meaning |
When to use it |
How to confirm |
Audience / permission |
Main input |
GET /api/v2/licensing/export/{licenseId} |
Read licensing / export / the selected licenseId. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Business API<br>authenticated |
licenseId (required) |
POST /api/v2/licensing/import |
Create or run licensing / import. |
Use it when the user submits this action or configuration change. |
Read the target resource again and verify both saved and runtime state. |
Business API<br>system.config.manage |
AkLicenseImportRequest |
GET /api/v2/licensing/request |
Read licensing / request. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Business API<br>authenticated |
No business input |
GET /api/v2/licensing/status |
Read licensing / status. |
Use it when loading a page, refreshing state, or searching current data. |
Use the returned data, paging totals, and current resource state. |
Business API<br>authenticated |
No business input |
Fields and examples
This page keeps business purpose readable. When coding, use the OpenAPI and Postman assets shipped with the deployed version for request bodies, response bodies, enums, file types, and examples. Do not use a newer website contract against an older service.