Xentree Docs
StatusMy Xentree
StatusMy Xentree
  1. Documentation
  • Documentation
    • Introduction
    • Quickstart
    • Authentication
    • Conversations
    • Knowledge Base
    • Organizations
    • Custom Domains
    • Admin Stats and Members
    • Profile & Analytics
    • Xentree English
    • Xentree Live
    • Skills Connector
    • Integration Tokens
    • API Keys
    • Errors and Limits
  • API Reference
    • Authentication
      • Register a new user
      • Log in and get an access token
      • Refresh an access token
      • Log out the current user
      • Get the current authenticated user
      • Update the current authenticated user
    • Conversations
      • List available AI providers
      • Generate an AI response
      • List conversations for the current user
      • Create a conversation
      • Delete a conversation
      • Get messages for a conversation
      • Start a conversation session
      • Update session activity
      • End a conversation session
      • Get current session status
      • Search indexed user content
      • Search infrastructure status
      • Rebuild search index
      • List notes
      • Create a note
      • Update a note
      • Delete a note
    • Knowledge Base
      • Search the knowledge base
      • List documents
      • Upload document
      • Query knowledge
    • Organizations
      • List organizations for the current user
      • Create an organization
      • Get organization details
      • Update organization details
      • Delete an organization
      • List organization members
      • Add a member to an organization
      • Update a member's role
      • Comprehensive member update (role, organization, team)
      • Remove a member from an organization
    • Custom Domains
      • Configure organization custom domain
      • Get organization custom-domain status
    • Admin Stats & Members
      • Engagement dashboard
      • Engagement member detail
      • Progress KPI cards
      • List learning objectives
      • Create learning objective
      • Archive learning objective
      • Suggest learning objectives (with draft)
      • Progress members table
      • Impact KPI cards
      • List learning targets
      • Create or update learning target
      • Suggest learning targets
      • Export admin stats report as PDF
      • Export admin stats report as XLSX
    • Profile & Analytics
      • Get my XP profile
      • Get a user's public profile
      • Get streak status
      • Get weekly XP activity
      • Get learning pulse (365-day heatmap)
      • Get daily quests
      • Get learning time analytics
    • Xentree English
      • List XEL modules with user progress
      • Get XEL module details
      • Start an XEL module
      • Complete an XEL module
      • Regenerate a task variant
      • Get current XPI breakdown
      • Get XPI history
      • Start a learning session
      • End a learning session
      • Save a transcript entry
      • Get transcripts for a session
      • Submit a learning task response
      • Run AI evaluation for speaking or writing
      • Get the XEL dashboard overview
    • Xentree Live
      • Get remaining Xentree Live quota
      • Start a live session
      • Update an active live session heartbeat
      • End a live session
      • Update the user nickname used in Xentree Live
      • List live transcripts for the current user
      • Save live session transcripts
      • Get a single live transcript
    • Skills Connector
      • List active integrations for the current user
      • Start the Google Calendar OAuth flow
    • Integration Tokens
      • Issue user- or organization-scoped RS256 integration grant token
      • Verify integration token signature and subject claims
      • Revoke integration token by token or jti
      • Rotate integration grant and optionally revoke previous token
      • Get active JWKS material for an integration subject
      • Get active integration key fingerprints for a subject
      • Admin observability for integration token revocations
    • API Keys
      • List API keys
      • Create an API key
      • Delete an API key
    • Health
      • Health check
      • Detailed health check
  • Schemas
    • Error
    • ConfigureCustomDomainRequest
    • SimpleDetailResponse
    • CustomDomainStatus
    • HealthLivenessResponse
    • HealthDetailedResponse
    • HealthDetailedServices
    • DatabaseHealthStatus
    • DatabasePoolStatus
    • DatabaseConnectionStats
    • SimpleMessageResponse
    • LogoutResponse
    • TokenResponse
    • UserProfile
    • ChatRequest
    • ChatResponse
    • ConversationCreateRequest
    • ConversationResponse
    • CoreSearchConversationResult
    • CoreSearchMessageResult
    • CoreSearchResponse
    • TypesenseReindexRequest
    • TypesenseStatusResponse
    • NoteCreate
    • NoteUpdate
    • NoteResponse
    • CoreConversationSessionStartResponse
    • CoreConversationSessionActivityResponse
    • CoreConversationSessionEndResponse
    • CoreConversationSessionStatusResponse
    • AdminStatsProgressMemberRow
    • TenantResponse
    • AdminStatsProgressMembersResponse
    • AdminStatsOrganizationSummary
    • AdminStatsDateRangeSummary
    • AdminStatsKPIStat
    • AdminStatsPulseDay
    • AdminStatsPulseSummary
    • AdminStatsTeamPulse
    • AdminStatsTrendPoint
    • AdminStatsDistributionBucket
    • AdminStatsCohortRetentionCell
    • AdminStatsCohortRetentionRow
    • AdminStatsCohortAnalyticsRow
    • AdminStatsCohortRetentionAnalytics
    • AdminStatsCohortRetentionResponse
    • AdminStatsMemberActivityRow
    • AdminStatsAffiliation
    • AdminStatsMemberDirectoryRow
    • AdminStatsDashboardResponse
    • AdminStatsUserDetailResponse
    • AdminStatsMutationResponse
    • ProgressKPIItem
    • ProgressKPIResponse
    • ProgressKeyResultPayload
    • ProgressObjectiveCreateRequest
    • ProgressObjectiveSuggestRequest
    • ProgressObjectiveKeyResult
    • ProgressObjectiveResponse
    • ProgressObjectiveSuggestedItem
    • ProgressObjectiveSuggestResponse
    • ProgressTrendResponse
    • ProgressMemberAttempt
    • ProgressMemberSession
    • ProgressMemberRow
    • ProgressMembersResponse
    • ProgressDistributionBucket
    • ProgressDistributionResponse
    • ImpactKPIItem
    • ImpactKPIResponse
    • ImpactTrendResponse
    • ImpactLevelItem
    • ImpactLevelProgressionResponse
    • ImpactTeamBreakdownItem
    • ImpactTeamBreakdownResponse
    • ImpactTopPerformerItem
    • ImpactTopPerformersResponse
    • LearningTargetCreateRequest
    • LearningTargetResponse
    • LearningTargetListResponse
    • LearningTargetSuggestResponse
    • LVIWeightResponse
    • LVIWeightUpdateRequest
    • IntegrationOut
    • KnowledgeSearchRequest
    • KnowledgeSearchResultItem
    • KnowledgeSearchResponse
    • RagDocument
    • RagUploadResponse
    • RagQueryRequest
    • RagQueryResponse
    • LiveStartSessionRequest
    • LiveSessionResponse
    • LiveQuotaResponse
    • TranscriptTurn
    • SaveLiveTranscriptsRequest
    • OrganizationCreateRequest
    • OrganizationResponse
    • MemberResponse
    • XELModuleSummary
    • XELTaskSubmissionRequest
    • XELModuleDetail
    • XELTaskSubmissionResponse
    • XELEvaluationResponse
    • XELDashboardResponse
    • XELModuleStartResponse
    • XELModuleCompleteResponse
    • XELTaskRegenerateRequest
    • XELTaskRegenerateResponse
    • XELXpiResponse
    • XELXpiHistoryItem
    • XELSessionStartRequest
    • XELSessionStartResponse
    • XELSessionEndRequest
    • XELSessionEndResponse
    • XELTranscriptSaveRequest
    • XELTranscriptSaveResponse
    • XELTranscriptItem
    • LiveSessionEndResponse
    • LiveSessionHeartbeatResponse
    • LiveNicknameResponse
    • LiveTranscriptSaveResponse
    • LiveTranscriptListItem
    • LiveTranscriptListResponse
    • LiveTranscriptDetailResponse
    • XPProfileResponse
    • PublicXPProfileResponse
    • StreakStatusResponse
    • WeeklyActivityResponse
    • LearningPulseDayEntry
    • APIKeyResponse
    • LearningPulseResponse
    • IntegrationGrantRequest
    • QuestItem
    • IntegrationGrantResponse
    • QuestsResponse
    • IntegrationVerifyRequest
    • LearningTimeAnalyticsResponse
    • IntegrationVerifyResponse
    • APIKeyCreateRequest
    • IntegrationRevokeRequest
    • IntegrationRevokeResponse
    • IntegrationJWKSResponse
    • IntegrationFingerprintResponse
    • IntegrationRotateRequest
    • IntegrationRotateResponse
    • IntegrationTokenRevocationItem
  1. Documentation

Integration Tokens

Integration Tokens provide short-lived server-to-server access grants. By default a grant is scoped to its issuing user. An organization administrator can explicitly request organization scope with organizationId.
Browser launches are handled by Xentree Connect: LMS sends a signed assertion by HTTP form POST, then Xentree redirects with an opaque, single-use ticket. Xentree never places bearer JWTs in URLs and does not support iframe or web-component embedding.
Tokens are signed with RS256 using per-subject key pairs. Each grant is short-lived, revocable, and bound to a specific set of scopes and an allowed origin.

Core capabilities#

issue short-lived RS256 integration grants
verify token validity and check JTI revocation status
revoke a token immediately by JTI
rotate a token (revoke old, issue new in one atomic call)
expose the per-subject JWKS endpoint for third-party verification
retrieve the public key fingerprint for out-of-band key pinning
admin observability of revoked tokens

Authentication and scopes#

All Integration Token endpoints require bearer or API key auth.
Recommended API key scopes:
integrations:read for verify, jwks, fingerprint
integrations:write for grant, revoke, rotate

REST endpoints#

Issue integration grant#

Issue a short-lived RS256-signed JWT for current user, or an explicitly selected organization.
POST /api/integration/grant
Representative request:
{
  "mode": "api",
  "origin": "https://partner.example.com",
  "scopes": ["profile:read", "quota:read"],
  "ttlSeconds": 120
}
Organization scope (caller must be that organization's administrator):
{
  "organizationId": "<organization-uuid>",
  "mode": "api",
  "origin": "https://partner.example.com"
}

Verify integration token#

Check validity and revocation status of an integration JWT.
POST /api/integration/verify

Revoke integration token#

Immediately invalidate a token by adding its JTI to the revocation list.
POST /api/integration/revoke

Rotate integration token#

Revoke an existing token and issue a fresh one atomically.
POST /api/integration/rotate

Subject JWKS#

Return active RS256 public keys for a user or organization subject in JWK Set format. Use subjectType and subjectId returned by grant response.
GET /api/integration/jwks
Query params: subjectType (user or organization), subjectId
This endpoint is public — no auth required.

Public key fingerprint#

Return the SHA-256 fingerprint of subject's active public key for out-of-band key pinning.
GET /api/integration/fingerprint
Query params: subjectType (user or organization), subjectId
This endpoint is public — no auth required.

Rate limits#

Grant and rotate operations are rate-limited per subject per principal. When the limit is exceeded, the API returns 429 Too Many Requests with the following headers:
HeaderDescription
X-RateLimit-LimitMaximum requests allowed in the window
X-RateLimit-RemainingRemaining requests in the current window
X-RateLimit-ResetUnix timestamp when the window resets
Retry-AfterSeconds to wait before retrying
Modified at 2026-08-18 07:55:52
Previous
Skills Connector
Next
API Keys
Built with