Tiyi v3.8.0

auth.proto — Authentication and session lifecycle

Schema: tiyi.v1 · auth.proto · English guide · 中文指南 · Full RPC index

Services

AuthService

RPC Kind Required permission
GetLoginOptions unary public (no token)
Login unary public (no token)
CompleteAuthenticationChallenge unary public (no token)
Logout unary public (no token)
Refresh unary public (no token)
GetUserInfo unary authenticated
GetAccessCodes unary authenticated
ChangePassword unary authenticated
GetMFAStatus unary authenticated
BeginTOTPEnrollment unary authenticated
ConfirmTOTPEnrollment unary authenticated
DisableTOTP unary authenticated
RegenerateRecoveryCodes unary authenticated

RPCs

AuthService.GetLoginOptions

Request — tiyi.v1.GetLoginOptionsRequest

No fields — send {}.

Response — tiyi.v1.GetLoginOptionsResponse

Field JSON key Type Cardinality Description
password_enabled passwordEnabled bool singular —
providers providers LoginProvider repeated —

AuthService.Login

Request — tiyi.v1.LoginRequest

Field JSON key Type Cardinality Description
username username string singular —
password password string singular —
remember remember bool singular —

Response — tiyi.v1.LoginResponse

Field JSON key Type Cardinality Description
access_token accessToken string singular —
expires_at expiresAt google.protobuf.Timestamp singular RFC 3339 string, e.g. 2026-07-26T09:00:00Z.
user user CurrentUser singular —
challenge_required challengeRequired bool singular —
challenge_kind challengeKind string singular —
challenge_prompt challengePrompt string singular —
recovery_code_allowed recoveryCodeAllowed bool singular —

AuthService.CompleteAuthenticationChallenge

Request — tiyi.v1.CompleteAuthenticationChallengeRequest

Field JSON key Type Cardinality Description
code code string singular —

Response — tiyi.v1.CompleteAuthenticationChallengeResponse

Field JSON key Type Cardinality Description
access_token accessToken string singular —
expires_at expiresAt google.protobuf.Timestamp singular RFC 3339 string, e.g. 2026-07-26T09:00:00Z.
user user CurrentUser singular —
challenge_required challengeRequired bool singular —
challenge_kind challengeKind string singular —
challenge_prompt challengePrompt string singular —
recovery_code_allowed recoveryCodeAllowed bool singular —

AuthService.Logout

Request — tiyi.v1.LogoutRequest

No fields — send {}.

Response — tiyi.v1.LogoutResponse

Field JSON key Type Cardinality Description
logged_out loggedOut bool singular —

AuthService.Refresh

Request — tiyi.v1.RefreshRequest

Field JSON key Type Cardinality Description
refresh_token refreshToken string singular —

Response — tiyi.v1.RefreshResponse

Field JSON key Type Cardinality Description
access_token accessToken string singular —
expires_at expiresAt google.protobuf.Timestamp singular RFC 3339 string, e.g. 2026-07-26T09:00:00Z.

AuthService.GetUserInfo

Request — tiyi.v1.GetUserInfoRequest

No fields — send {}.

Response — tiyi.v1.GetUserInfoResponse

Field JSON key Type Cardinality Description
user user CurrentUser singular —

AuthService.GetAccessCodes

Request — tiyi.v1.GetAccessCodesRequest

No fields — send {}.

Response — tiyi.v1.GetAccessCodesResponse

Field JSON key Type Cardinality Description
codes codes string repeated —

AuthService.ChangePassword

Request — tiyi.v1.ChangePasswordRequest

Field JSON key Type Cardinality Description
current_password currentPassword string singular —
new_password newPassword string singular —

Response — tiyi.v1.ChangePasswordResponse

Field JSON key Type Cardinality Description
changed changed bool singular —

AuthService.GetMFAStatus

Request — tiyi.v1.GetMFAStatusRequest

No fields — send {}.

Response — tiyi.v1.GetMFAStatusResponse

Field JSON key Type Cardinality Description
totp_enabled totpEnabled bool singular —
enabled_at enabledAt google.protobuf.Timestamp singular RFC 3339 string, e.g. 2026-07-26T09:00:00Z.
recovery_codes_left recoveryCodesLeft int32 singular —

AuthService.BeginTOTPEnrollment

Request — tiyi.v1.BeginTOTPEnrollmentRequest

No fields — send {}.

Response — tiyi.v1.BeginTOTPEnrollmentResponse

Field JSON key Type Cardinality Description
enrollment_token enrollmentToken string singular —
secret secret string singular —
provisioning_uri provisioningUri string singular —
expires_at expiresAt google.protobuf.Timestamp singular RFC 3339 string, e.g. 2026-07-26T09:00:00Z.

AuthService.ConfirmTOTPEnrollment

Request — tiyi.v1.ConfirmTOTPEnrollmentRequest

Field JSON key Type Cardinality Description
enrollment_token enrollmentToken string singular —
code code string singular —

Response — tiyi.v1.ConfirmTOTPEnrollmentResponse

Field JSON key Type Cardinality Description
enabled enabled bool singular —
recovery_codes recoveryCodes string repeated —

AuthService.DisableTOTP

Request — tiyi.v1.DisableTOTPRequest

Field JSON key Type Cardinality Description
code code string singular —

Response — tiyi.v1.DisableTOTPResponse

Field JSON key Type Cardinality Description
disabled disabled bool singular —

AuthService.RegenerateRecoveryCodes

Request — tiyi.v1.RegenerateRecoveryCodesRequest

Field JSON key Type Cardinality Description
code code string singular —

Response — tiyi.v1.RegenerateRecoveryCodesResponse

Field JSON key Type Cardinality Description
recovery_codes recoveryCodes string repeated —

Messages

CurrentUser

Field JSON key Type Cardinality Description
id id string singular —
tenant_id tenantId string singular —
username username string singular —
email email string singular —
display_name displayName string singular —
roles roles string repeated —
access_codes accessCodes string repeated —

LoginProvider

Field JSON key Type Cardinality Description
id id string singular —
label label string singular —
login_url loginUrl string singular —