MobiariDocs

Sign in

POST
/auth/login

Checks e-mail and password. Without two-factor authentication the response has status: "authenticated" and a session (access token, refresh token, user). With it, status: "two_factor_required" and a challenge valid for 5 minutes: finish with POST /auth/2fa/totp/verify or POST /auth/otp/send + POST /auth/otp/verify, depending on methods.

Header Parameters

Idempotency-Key?string

A unique value (e.g. a UUID) per logical request. Retrying with the same key within 24 hours replays the first response instead of repeating the side effect; the replay carries Idempotent-Replayed: true. Reusing a key for a different request is a 422 idempotency_key_reused; retrying while the first is still running is a 409 idempotency_request_in_progress. JSON bodies up to 1 MB.

Lengthlength <= 255

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/login" \  -H "Content-Type: application/json" \  -d '{    "email": "ana@example.com",    "password": "string"  }'
{
  "expires_in": 86400,
  "refresh_token": "string",
  "refresh_token_expires_in": 2592000,
  "session_id": "1ffd059c-17ea-40a8-8aef-70fd0307db82",
  "token": "string",
  "token_type": "Bearer",
  "user": {
    "created_at": "2019-08-24T14:15:22Z",
    "email": "string",
    "full_name": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "is_active": true,
    "locale": null,
    "phone": "string",
    "totp_enabled": true,
    "whatsapp_2fa_enabled": true
  },
  "status": "authenticated"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}