Skip to main content

Overview

AWX supports multiple authentication methods for API access. All API requests must be authenticated unless accessing public endpoints.

Authentication Methods

AWX supports the following authentication methods based on the source code (awx/api/authentication.py):

1. Session Authentication

Session-based authentication using Django sessions. Primarily used by the web UI.

2. Basic Authentication

HTTP Basic Authentication with username and password. Must be enabled via AUTH_BASIC_ENABLED setting.
Basic authentication must be enabled in AWX settings. It is logged for audit purposes.

3. OAuth 2.0 Token Authentication

The recommended method for API access using bearer tokens.

Create an OAuth Token

string
The bearer token to use for authentication
string
Token used to refresh the access token
string
Token expiration timestamp

Use the Token

4. Application OAuth Tokens

Create OAuth2 applications for third-party integrations.

Create an Application

string
OAuth client identifier
string
OAuth client secret (confidential clients only)

Token Management

List Your Tokens

Revoke a Token

Token Scopes

Tokens can have different scopes:
  • read - Read-only access
  • write - Read and write access (default)

Current User Information

Get information about the authenticated user:
integer
User ID
string
Username
string
Email address
boolean
Whether user has superuser privileges
boolean
Whether user has system auditor role

Login and Logout Endpoints

Login

Creates a session. Returns session cookie.
string
required
Username
string
required
Password

Logout

Invalidates the current session.

Security Best Practices

Prefer OAuth tokens over basic authentication. Tokens can be revoked and have expiration times.
Always use HTTPS in production to protect credentials and tokens in transit.
Create new tokens periodically and revoke old ones to minimize security risks.
Use read-only tokens when write access is not needed.
Never commit tokens to source control. Use environment variables or secret management systems.

Authentication Errors

401 Unauthorized

Missing or invalid authentication credentials:

403 Forbidden

Valid authentication but insufficient permissions:

Example: Complete Authentication Flow

Proxy and Gateway Authentication

AWX supports trusted proxy authentication via the X-Trusted-Proxy header for integration with authentication gateways. This is configured via REMOTE_HOST_HEADERS and PROXY_IP_ALLOWED_LIST settings.