← Back to Sample APIs

Addition — With Bearer Token (JWT)

Adds two integers, but requires a valid JWT in the Authorization: Bearer header. This is the OAuth 2.0 / token-based auth pattern used by modern APIs.

Concept: Bearer Token · JWT Verification · OAuth-style
Addition API Series — same operation, different style
01

Endpoint

GET https://labs.lowcademy.com/apis/add-bearer?input1=5&input2=3
Pre-requisite: Get a token first from add-token.php. Then pass it as Authorization: Bearer <token>. Token expires in 1 hour.
02

Authentication — Bearer Token

A JWT (JSON Web Token) is a signed, self-contained token. The server verifies the signature and expiry without needing to look up the token in a database.

HeaderValue
AuthorizationBearer <JWT from add-token.php>
03

Query Parameters

ParameterTypeRequiredDescription
input1IntegerRequiredFirst integer
input2IntegerRequiredSecond integer
04

Sample Requests

Step 1 — Get the token

TOKEN=$(curl -s -X POST https://labs.lowcademy.com/apis/add-token \
        -H "Content-Type: application/json" \
        -d '{"api_key":"lc-api-key-2024","api_secret":"lc@Secret#2024"}' | jq -r .token)

Step 2 — Call the API with the token

curl -H "Authorization: Bearer $TOKEN" \
     https://labs.lowcademy.com/apis/add-bearer?input1=5&input2=3

JavaScript (fetch, both steps)

// Step 1: Get token
const tr  = await fetch('https://labs.lowcademy.com/apis/add-token', {
  method : 'POST',
  headers: { 'Content-Type': 'application/json' },
  body   : JSON.stringify({ api_key: 'lc-api-key-2024', api_secret: 'lc@Secret#2024' })
});
const { token } = await tr.json();

// Step 2: Use token
const res  = await fetch('https://labs.lowcademy.com/apis/add-bearer?input1=5&input2=3', {
  headers: { 'Authorization': 'Bearer ' + token }
});
const data = await res.json();
console.log(data.result); // 8
05

Response — 200 OK

{
  "success"    : true,
  "auth_method": "Bearer Token (JWT)",
  "operation"  : "addition",
  "input1"     : 5,
  "input2"     : 3,
  "result"     : 8
}
06

Error Responses

200
OK
401
Unauthorized — Missing, invalid, or expired Bearer token. Get a fresh one from add-token.php.
400
Bad Request — Missing or non-numeric parameters.
405
Method Not Allowed