# Authenticating API for users

**URL:** <https://forum.ghost.org/t/authenticating-api-for-users/36422>\
**Category:** Integrations & API\
**Created:** [February 16, 2023, 3:15am UTC](https://forum.ghost.org/t/authenticating-api-for-users/36422 "2023-02-16T03:15:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Unmarked4564](https://avatars.discourse-cdn.com/v4/letter/u/848f3c/32.png) [@Unmarked4564](https://forum.ghost.org/u/Unmarked4564)\
**Post date:** [February 16, 2023, 3:15am UTC](https://forum.ghost.org/t/authenticating-api-for-users/36422/1 "2023-02-16T03:15:22Z")

</div>

I want to build a custom, external api to display some stats that are tied to the users’ accounts. I can keep track of the users through webhooks, but how do I allow them to access their own data securely?

To sum it up: How can I use ghost’s internal authentication with an external application?

---

<div class="post-metadata">

**Author:** ![hwlmatt](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/hwlmatt/32/16298_2.png) [@hwlmatt](https://forum.ghost.org/u/hwlmatt)\
**Post date:** [February 16, 2023, 9:17pm UTC](https://forum.ghost.org/t/authenticating-api-for-users/36422/2 "2023-02-16T21:17:25Z")

</div>

You can get a JWT for a logged in user by hitting `/members/api/session/`  
(this is current as of v5, the endpoint on the link below is out of date).

Pass that to app, and have app validate it.  
the Public Key is at ` /members/.well-known/jwks.json`

> [@Use Ghost members auth to log-in to custom app via cookies](https://forum.ghost.org/t/use-ghost-members-auth-to-log-in-to-custom-app-via-cookies/12608/4):
>
> Hey! This is definitely doable but it’s gonna be a hack either way as these are not publicly documented or stable methods. You can either get a JWT for a member and use that to authenticate into your application, but this won’t handle logout when the member logs out of Ghost. Or you can use the cookies like you say, but this will be a little more involved and require your app to be running on the same domain so that the cookies can be shared. External auth with JWT You can make a GET request…

---

<div class="post-metadata">

**Author:** ![Unmarked4564](https://avatars.discourse-cdn.com/v4/letter/u/848f3c/32.png) [@Unmarked4564](https://forum.ghost.org/u/Unmarked4564)\
**Post date:** [February 17, 2023, 12:08am UTC](https://forum.ghost.org/t/authenticating-api-for-users/36422/3 "2023-02-17T00:08:11Z")

</div>

> [@hwlmatt](#):
>
> the Public Key is at /members/.well-known/jwks.json

I am having trouble with this part, I found `./versions/5.34.0/core/server/web/well-known.js` which has the jwks.json route `wellKnownApp.get('/jwks.json', cache, async (req, res) => `, but I can’t seem to get it to respond with anything other than a 404. Is there some change I need to make? I did notice anything on the `/members/.well-known/` path returns an nginx 404 instead of one from ghost. [https://github.com/TryGhost/Ghost/search?q=jwks.json](https://github.com/TryGhost/Ghost/search?q=jwks.json) This was somewhat useful, it seems I might have some sort of installation issue as the routes listed don’t function on my server. I tested on a public installation of ghost and it worked fine so it must be an issue with my nginx I think.

---

<div class="post-metadata">

**Author:** ![Unmarked4564](https://avatars.discourse-cdn.com/v4/letter/u/848f3c/32.png) [@Unmarked4564](https://forum.ghost.org/u/Unmarked4564)\
**Post date:** [February 17, 2023, 12:32am UTC](https://forum.ghost.org/t/authenticating-api-for-users/36422/4 "2023-02-17T00:32:52Z")

</div>

Update: solved the issue with nginx. Had to comment some lines out that the cli installer made in the two files in sites-avaliable and its working fine now.

```auto
    #location ~ /.well-known {
    # allow all;
    #}

```

---

<div class="post-metadata">

**Author:** ![Unmarked4564](https://avatars.discourse-cdn.com/v4/letter/u/848f3c/32.png) [@Unmarked4564](https://forum.ghost.org/u/Unmarked4564)\
**Post date:** [February 17, 2023, 1:01am UTC](https://forum.ghost.org/t/authenticating-api-for-users/36422/5 "2023-02-17T01:01:03Z")

</div>

Just a tip for anyone trying to follow along, [https://token.dev/](https://token.dev/) is a great resource. Helped me understand how these things work
