Environments
The platform runs in two environments. Each has its own API host and its own sign-in server; data, tenants, user profiles and API keys are not shared between them.
| Production | Develop | |
|---|---|---|
| API base URL | https://api.mosterd.com | https://api.develop.mosterd.com |
| Sign-in server (Auth0 domain) | login.rulebooks.ai | login.develop.rulebooks.nl |
Token issuer (iss) | https://login.rulebooks.ai/ | https://login.develop.rulebooks.nl/ |
Audience (aud) | https://api.mosterd | https://api.mosterd |
All paths in this API reference are relative to the base URL. For example, listing the companies of a tenant on develop:
GET https://api.develop.mosterd.com/data/2f9c6e1a-7b34-4d58-9c21-0a5e8f1b2c3d/companies
Auth0 endpoints
The sign-in servers are Auth0 tenants on a custom domain, so they expose the standard Auth0 and OpenID Connect endpoints. Replace {domain} with the sign-in server of the environment:
| Endpoint | URL |
|---|---|
| OpenID Connect discovery | https://{domain}/.well-known/openid-configuration |
| Authorize (browser sign-in) | https://{domain}/authorize |
| Token | https://{domain}/oauth/token |
| Signing keys (JWKS) | https://{domain}/.well-known/jwks.json |
| User info | https://{domain}/userinfo |
| Log out | https://{domain}/v2/logout |
Always request tokens with audience=https://api.mosterd. The audience is the same in both environments; the issuer is not, so a token from the develop sign-in server is rejected by the production API and vice versa.
See Authentication for how tokens and API keys are presented to the API.