> ## Documentation Index
> Fetch the complete documentation index at: https://docs.awardforce.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Retrieve a user auth token

> Retrieves an SSO auth token for the specified user.

Use the token to log the user into the app using SSO.

<Card title="Creating your own SSO integration" icon="key" href="https://support.awardforce.com/hc/en-us/articles/360002282716-Creating-your-own-SSO-integration">
  Learn how to integrate Award Force with your own SSO provider.
</Card>


## OpenAPI

````yaml /api-reference/openapi-v2_3.yaml get /user/{user_slug}/auth-token
openapi: 3.1.0
info:
  title: Award Force API
  version: '2.3'
  description: >
    The Award Force API enables you to programmatically manage awards,
    competitions, scholarships, and recognition programs.


    Use this API to:

    - Create and manage entries and submissions

    - Automate judging workflows and assignments

    - Process entry fees and payments

    - Generate reports and analytics

    - Integrate with external systems via webhooks


    All API requests require authentication using an API key provided in the
    `X-Api-Key` header.
  license:
    name: Creative Force Client Subscription Terms
    url: https://creativeforce.team/agreement/
servers:
  - url: https://api.us.cr4ce.com
    description: US regional endpoint
  - url: https://api.eu.cr4ce.com
    description: EU regional endpoint
  - url: https://api.au.cr4ce.com
    description: Australasia regional endpoint
  - url: https://api.ca.cr4ce.com
    description: Canada regional endpoint
  - url: https://api.hk.cr4ce.com
    description: Hong Kong regional endpoint
security:
  - ApiKeyAuth: []
tags:
  - name: Account
    description: >-
      Use this operation to retrieve information about your organization
      account.

      The account resource provides metadata about the tenant associated with
      your API key.


      Note: Account information is read-only and contains organization-level
      settings and identifiers.
  - name: Assignments
    description: >-
      Use these operations to manage judging assignments for evaluating entries.

      Assignments connect judges (or roles) with entries and score sets to
      facilitate the review process.


      Assignments can be created individually or in bulk (asynchronous
      operations).

      Each assignment tracks completion status, scores, and panel membership.

      Assignments enable structured evaluation workflows with configurable score
      sets.
  - name: Attachments
    description: >-
      Use these operations to manage files uploaded to entries through
      attachment tabs.

      Attachments are distinct from field-based file uploads and allow for
      supplementary materials.


      Each attachment can have its own metadata and custom fields for
      categorization.

      Attachments remain associated with their entry throughout the entry
      lifecycle.
  - name: Categories
    description: >-
      Use these operations to manage competition categories or award divisions.

      Categories organize entries into logical groups and can be hierarchical
      with parent-child relationships.


      Each category can have its own entry form, chapter availability, entry
      limits, and custom labels.

      Categories support translated names and descriptions for multi-language
      programs.
  - name: Chapters
    description: >-
      Use these operations to manage geographic or organizational divisions
      within your programs.

      Chapters enable you to run regional competitions, manage local awards, or
      organize by business units.


      Entries can be assigned to chapters, and chapters can have their own
      administrators and configurations.

      Chapters support translated names and custom images for branding.
  - name: Contributors
    description: >-
      Use these operations to manage additional people associated with entries
      beyond the primary entrant.

      Contributors represent team members, collaborators, or co-authors on a
      submission.


      Each contributor can have their own custom fields and data collection
      requirements.

      Contributors are organized by tabs and can be managed independently from
      the main entry.
  - name: Documents
    description: >-
      Use these operations to generate and retrieve PDF documents and data
      exports.

      Documents can be created based on entry data, user data, or other program
      information.


      Document generation is asynchronous - after creating a document, poll the
      endpoint to check when generation is complete.

      Generated documents are available for download and can be associated with
      specific entrants or entries.
  - name: Entries
    description: >-
      Use these operations to manage entries (submissions) to your awards,
      competitions, or recognition programs.

      Entries are the core entity that flows through the entire lifecycle from
      submission to judging to winner selection.


      Entries can contain custom form fields, file uploads, contributors, and be
      organized by categories and chapters.

      Each entry goes through various statuses including draft, submitted, under
      review, and finalist stages.
  - name: Entries (realtime)
    description: >-
      Use these operations to perform granular updates on entries without
      replacing the entire resource.

      These endpoints enable real-time updates to specific entry properties such
      as:

      title, category assignment, chapter assignment, individual field values,
      file uploads, tags, and recusal status.


      These operations are optimized for interactive programs that need to
      update entries incrementally.
  - name: Fields
    description: >-
      Use these operations to manage custom form fields used to collect data
      throughout your programs.

      Fields can be attached to entries, users, contributors, attachments, and
      other resources.


      Supported field types include text, textarea, select, multi-select, date,
      file upload, table, and more.

      Fields support conditional logic, validation rules, and different
      protection levels.

      Note: Field deletion and updates are managed through the Award Force
      interface.
  - name: Files
    description: >-
      Use these operations to retrieve information about uploaded files.

      Files provide metadata and download links for content uploaded throughout
      the system.


      Access files using their secure token identifiers.

      Note: Files are read-only via this endpoint - file uploads are handled
      through resource-specific upload endpoints.
  - name: Leaderboard
    description: >-
      Use these operations to retrieve ranking results and scores for entries.

      The leaderboard shows how entries rank based on score sets, with support
      for filtering by category, chapter, and tags.


      Results can be filtered to show specific subsets of the competition.

      Note: The leaderboard is read-only and reflects calculated results from
      the judging process.
  - name: Orders
    description: >-
      Use these operations to manage payment transactions for entry fees and
      other charges.

      Orders represent financial transactions processed through your program.


      Each order contains line items, tracks payment status, and can operate in
      test or live mode.

      Orders are associated with seasons and can be queried for financial
      reporting.
  - name: Review tasks
    description: >-
      Use these operations to manage individual review and evaluation
      activities.

      Review tasks represent specific actions that judges or administrators need
      to complete during the evaluation process.


      Tasks track timestamps, decisions, and judge associations.

      Review tasks integrate with the broader judging workflow and status
      tracking.
  - name: Rounds
    description: >-
      Use these operations to retrieve round information for your programs.

      Rounds represent phases within a season, such as entry rounds, judging
      rounds, or finalist rounds.


      Each round has specific start and end dates, associated forms, and can be
      scoped to specific chapters.

      Note: Rounds are read-only via the API and must be managed through the
      Award Force interface.
  - name: Score sets
    description: >-
      Use these operations to retrieve score set configurations and evaluation
      criteria.

      Score sets define the questions, scales, and calculation methods used to
      evaluate entries.


      Score sets can operate in different modes including judging, ranking, and
      decision-making.

      Note: Score sets are read-only via the API and must be configured through
      the Award Force interface.
  - name: Seasons
    description: >-
      Use these operations to retrieve information about seasons (program
      cycles).

      A season represents a time-bound program instance, such as "2026 Awards"
      or "Q1 2026 Scholarship Round".


      Seasons contain forms, rounds, categories, and chapters.

      Seasons progress through statuses: draft, active, archived, and destroyed.

      Note: Seasons are read-only via the API and must be managed through the
      Award Force interface.
  - name: Taxes
    description: >-
      Use these operations to retrieve tax configurations for financial
      transactions.

      Tax settings define how taxes are calculated and applied to orders and
      payments.


      Note: Tax configurations are read-only via the API and must be managed
      through the Award Force interface.
  - name: Users
    description: >-
      Use these operations to manage user accounts in your organization.

      Users represent people who interact with your programs, including
      entrants, judges, administrators, and other roles.


      Users can be assigned roles, have custom profile fields, receive
      notifications, and authenticate via API tokens.

      Each user has a unique slug identifier and can participate across multiple
      seasons.
  - name: Webhooks
    description: >-
      Use these operations to manage webhook subscriptions for real-time event
      notifications.

      Webhooks notify your external systems when events occur in Award Force,
      such as entry submissions, status changes, or payment completions.


      Available events include: entry created, entry submitted, entry status
      changed, payment success, user confirmed, and 20+ more.

      Configure webhooks to send HTTP POST requests to your specified URLs with
      event payloads.
paths:
  /user/{user_slug}/auth-token:
    parameters:
      - $ref: '#/components/parameters/userSlug'
    get:
      tags:
        - Users
      summary: Retrieve a user auth token
      description: Retrieves an SSO auth token for the specified user.
      operationId: GetUserAuthTokenV23
      parameters:
        - $ref: '#/components/parameters/Accept'
      responses:
        '200':
          description: Auth token retrieved.
          headers:
            ETag:
              $ref: '#/components/headers/ETag'
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthToken'
            application/xml:
              schema:
                $ref: '#/components/schemas/AuthToken'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/TooManyRequests'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
components:
  parameters:
    userSlug:
      name: user_slug
      in: path
      required: true
      description: User slug
      schema:
        type: string
        pattern: ^[A-Za-z]{8}$
    Accept:
      name: Accept
      in: header
      required: true
      description: Defines the response type.
      schema:
        type: string
        enum:
          - application/vnd.Creative Force.v2.3+json
          - application/vnd.Creative Force.v2.3+xml
  headers:
    ETag:
      description: Entity tag for the selected representation.
      schema:
        type: string
    X-RateLimit-Limit:
      description: Maximum number of requests allowed per minute.
      schema:
        type: integer
        example: 60
    X-RateLimit-Remaining:
      description: Number of requests remaining in the current rate limit window.
      schema:
        type: integer
        example: 58
    X-RateLimit-Reset:
      description: Unix timestamp when the rate limit window resets.
      schema:
        type: integer
        example: 1783470988
    Retry-After:
      description: Number of seconds the client should wait before retrying.
      schema:
        type: integer
      example: 60
  schemas:
    AuthToken:
      type: object
      title: AuthToken
      description: |-
        Single-use SSO auth token for the specified user.

        Use the token to log the user into the app via SSO.
      properties:
        auth_token:
          type: string
          description: Opaque SSO auth token for the user.
      example:
        auth_token: AbCdEfGhIjKlMnOpQrStUvWxYz012345
    BadRequest:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 400
              maximum: 400
    Unauthorized:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 401
              maximum: 401
    Forbidden:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 403
              maximum: 403
    NotFound:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 404
              maximum: 404
    TooManyRequests:
      allOf:
        - $ref: '#/components/schemas/BaseProblem'
        - type: object
          properties:
            status_code:
              type: integer
              minimum: 429
              maximum: 429
    BaseProblem:
      description: Standard error envelope shared by every error response on this API.
      type: object
      properties:
        message:
          type: string
        status_code:
          type: integer
          minimum: 400
          maximum: 599
  responses:
    BadRequest:
      description: >-
        Request was rejected before the endpoint could process it. Common
        causes: invalid `Accept` header, unsupported `x-api-language` code,
        empty request body on `POST` / `PUT`, invalid JSON in the request body,
        or an invalid slug format in a path parameter.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/BadRequest'
        application/xml:
          schema:
            $ref: '#/components/schemas/BadRequest'
    Unauthorized:
      description: Missing `x-api-key` header.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Unauthorized'
        application/xml:
          schema:
            $ref: '#/components/schemas/Unauthorized'
    Forbidden:
      description: |-
        Authenticated request denied. Common causes: invalid or unknown
        API key, suspended account, or `api` feature not enabled for
        the account.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Forbidden'
        application/xml:
          schema:
            $ref: '#/components/schemas/Forbidden'
    NotFound:
      description: >-
        Resource identified by the path slug does not exist. Returned when the
        slug is well-formed but no record matches it.
      headers:
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/NotFound'
        application/xml:
          schema:
            $ref: '#/components/schemas/NotFound'
    TooManyRequests:
      description: Rate limit of 60 requests per minute exceeded.
      headers:
        Retry-After:
          $ref: '#/components/headers/Retry-After'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/TooManyRequests'
        application/xml:
          schema:
            $ref: '#/components/schemas/TooManyRequests'
    ServiceUnavailable:
      description: Service is temporarily unavailable due to regional maintenance.
      content:
        application/json:
          schema:
            type: object
            properties:
              status:
                type: string
                description: Human-readable maintenance status.
            example:
              status: Maintenance in progress
        application/xml:
          schema:
            type: object
            properties:
              status:
                type: string
                description: Human-readable maintenance status.
            example:
              status: Maintenance in progress
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: |-
        API key used to authenticate and authorise every request.
        Include it in the `x-api-key` header.

````