<a id="devlxd-authenticate"></a>

# How to authenticate to the DevLXD API

The DevLXD API is available inside guest instances to allow limited interaction with the host (see [Communication between instance and host](https://canonical.com/lxd/docs/latest/dev-lxd/index.html.md#dev-lxd)).

This API is available unauthenticated, since LXD determines the source instance and returns information only for that workload.
However, advanced use cases may require the caller to be authenticated.

To authenticate over the DevLXD API, first create a `DevLXD token bearer` identity:

CLI

```bash
lxc auth identity create devlxd/<name> [[--group <group> ]]
```

The new identity initially has type `DevLXD token bearer (pending)`.
A pending identity cannot authenticate but can be added to groups.

Next, issue a token for the identity (this changes its type to `DevLXD token bearer`):

```bash
lxc auth identity token issue devlxd/<name> [--expiry <expiry> ]
```

API

```bash
lxc query --request POST /1.0/auth/identities/bearer --data '{
  "name": "<name>",
  "type": "DevLXD token bearer",
  "groups": [
    "<group>"
  ]
}'
```

Next, issue a token for the identity:

```bash
lxc query --request POST /1.0/auth/identities/bearer/<name>/token --data '{
  "expiry": "<expiry>"
}'
```

UI

Click Permissions in the navigation sidebar, then select Identities from the expanded drop-down list.

Click on the + Create identity button to open the side panel.

Select Bearer token (DevLXD). Enter a name and optionally a token expiry for the new identity. Select relevant authentication group(s), then click Create identity.

In the modal, click the copy button <span class='guilabel'><svg width='16' height='16' xmlns='http://www.w3.org/2000/svg' aria-hidden='true' style='display:inline-block;vertical-align:text-bottom'><path d='M13.731 10v2.274h2.275v1.5h-2.275v2.232h-1.5v-2.232H10v-1.5h2.231V10h1.5zM11 4.948H5V3.5H3.5v10h5V15h-5A1.5 1.5 0 012 13.5v-10A1.5 1.5 0 013.5 2h1.67a3.001 3.001 0 015.66 0h1.67A1.5 1.5 0 0114 3.5v3.709h-1.5V3.5H11v1.448zM8 1.5a1.5 1.5 0 00-1.493 1.356L6.5 3v.447h3V3a1.5 1.5 0 00-1.356-1.493L8 1.5z' fill='currentColor' fill-rule='nonzero'/></svg></span> to copy the token.

The returned token can be used to authenticate with LXD over the DevLXD socket.
It must be set as a bearer token in the `Authorization` header.

You can verify trust by checking the `auth` field in the response of `GET /1.0`:

```none
$ lxc exec c1 --env TOKEN=${token} -- bash
root@c1# curl -H "Authorization: Bearer ${TOKEN}" -s --unix-socket /dev/lxd/sock http://custom.socket/1.0
{"state":"Started","api_version":"1.0","instance_type":"container","location":"my-host","auth":"trusted"}
```
