Login user

Authenticates a user and returns access token

POST/api/v1/:app_id/auth/login
API
Auth
OpenAPI
auth-api
Updated
Apr 26, 2026

auth-api:POST:/api/v1/:app_id/auth/login

Authenticates a user and returns access token

API ownership

  • API family: Auth API
  • Best for: Customer identity, session, token, cart, and wishlist flows.
  • Do not use from: Merchant admin data syncs or public catalog rendering.
  • Guide route: /apis/auth/latest

The OpenAPI contract defines the method, path, parameters, request body, and responses for this operation.

Operation

  • Method: POST
  • Path: /api/v1/:app_id/auth/login
  • Summary: Login user
  • Description: Authenticates a user and returns access token
  • OpenAPI contract: auth-api
  • Operation ID: Not documented in the OpenAPI contract.

Operation key uses API family, method, and path because this OpenAPI contract does not publish an operation ID.

Parameters1 parameter
NameInRequiredTypeDescription
app_idpathYesstringUUID of the app
Request bodyDocumented body
  • Required: Yes
  • Description: Login credentials
  • Content: application/json (object)

Login Request

PropertyTypeRequiredDetails
emailstringYes-
passwordstringYesminLength: 8

Generated example (synthetic):

{
  "email": "string",
  "password": "string"
}
Responses4 statuses
StatusDescriptionContent
200OKapplication/json (object)
400Invalid requestapplication/json (object)
401Invalid credentialsapplication/json (object)
500Internal server errorapplication/json (object)

200 - object

Login

PropertyTypeRequiredDetails
access_tokenstringNo-
expires_inintegerNo-
refresh_tokenstringNo-
token_typestringNo-
userobjectNo-
User
PropertyTypeRequiredDetails
additionsobjectNo-
addressobjectNo-
app_idstringNo-
attributesobject[]No-
communication_preferencesobjectNo-
created_atstringNo-
customer_groupsobject[]No-
emailstringNo-
email_verifiedbooleanNo-
filesobject[]No-
first_namestringNo-
idstringNo-
is_super_adminbooleanNo-
languagestringNo-
last_login_atstringNo-
last_namestringNo-
marketstringNo-
market_currencystringNo-
market_idstringNo-
organisationsobject[]No-
phone_numberstringNo-
statusstringNo-
store_groupstringNo-
store_group_idstringNo-
tagsobject[]No-
updated_atstringNo-
Address
PropertyTypeRequiredDetails
citystringNo-
countrystringNo-
country_codestringNo-
streetstringNo-
zip_codestringNo-
Attribute
PropertyTypeRequiredDetails
descriptionstringNo-
idstringNo-
keystringNo-
namestringNo-
template_keystringNo-
translationsobjectNo-
valuesobjectNo-
Communication Preferences
PropertyTypeRequiredDetails
allow_emailbooleanNo-
allow_postalbooleanNo-
allow_smsbooleanNo-
Customer Group Ref
PropertyTypeRequiredDetails
idstringNo-
namestringNo-
slugstringNo-
File
PropertyTypeRequiredDetails
app_idstringNo-
content_typestringNo-
created_atstringNo-
custom_fieldsobjectNo-
filenamestringNo-
idstringNo-
updated_atstringNo-
urlstringNo-
Organisation With User Relation
PropertyTypeRequiredDetails
app_idstringNo-
attributesobject[]No-
billing_addressobject[]No-
commentstringNo-
contact_namestringNo-
created_atstringNo-
credit_checkbooleanNo-
custom_fieldsobjectNo-
customer_groupsobject[]No-
emailstringNo-
external_refstringNo-
filesobject[]No-
idstringNo-
invoice_emailstringNo-
levelstringNoCan be null when a child organisation is without this user relation
namestringNo-
organisation_numberstringNo-
parent_idstringNo-
phonestringNo-
rolestringNoCan be null when a child organisation is without this user relation
role_namestringNoCan be null when a child organisation is without this user relation
shipping_addressobject[]No-
statusstringNo-
store_groupsobject[]No-
tagsobject[]No-
tax_id_vat_numberstringNo-
updated_atstringNo-
Tag
PropertyTypeRequiredDetails
idstringNo-
keystringNo-
namestringNo-
{
  "access_token": "string",
  "expires_in": 0,
  "refresh_token": "string",
  "token_type": "string",
  "user": {
    "additions": {},
    "address": {
      "city": "string",
      "country": "string",
      "country_code": "string",
      "street": "string",
      "zip_code": "string"
    },
    "app_id": "string",
    "attributes": [
      {
        "description": "string",
        "id": "string",
        "key": "string",
        "name": "string",
        "template_key": "string",
        "translations": {
          "description": null,
          "name": null
        },
        "values": {}
      }
    ],
    "communication_preferences": {
      "allow_email": false,
      "allow_postal": false,
      "allow_sms": false
    },
    "created_at": "string",
    "customer_groups": [
      {
        "id": "string",
        "name": "string",
        "slug": "string"
      }
    ],
    "email": "string",
    "email_verified": false,
    "files": [
      {
        "app_id": "string",
        "content_type": "string",
        "created_at": "string",
        "custom_fields": {},
        "filename": "string",
        "id": "string",
        "updated_at": "string",
        "url": "string"
      }
    ],
    "first_name": "string",
    "id": "string",
    "is_super_admin": false,
    "language": "string",
    "last_login_at": "string",
    "last_name": "string",
    "market": "string",
    "market_currency": "string",
    "market_id": "string",
    "organisations": [
      {
        "app_id": "string",
        "attributes": [],
        "billing_address": [],
        "comment": "string",
        "contact_name": "string",
        "created_at": "string",
        "credit_check": false,
        "custom_fields": {},
        "customer_groups": [],
        "email": "string",
        "external_ref": "string",
        "files": [],
        "id": "string",
        "invoice_email": "string",
        "level": "string",
        "name": "string",
        "organisation_number": "string",
        "parent_id": "string",
        "phone": "string",
        "role": "string",
        "role_name": "string",
        "shipping_address": [],
        "status": "string",
        "store_groups": [],
        "tags": [],
        "tax_id_vat_number": "string",
        "updated_at": "string"
      }
    ],
    "phone_number": "string",
    "status": "string",
    "store_group": "string",
    "store_group_id": "string",
    "tags": [
      {
        "id": "string",
        "key": "string",
        "name": "string"
      }
    ],
    "updated_at": "string"
  }
}

400 - object

Error Message

PropertyTypeRequiredDetails
detailsstring[]No-
messagestringNo-
successbooleanNo-

Generated example (synthetic):

{
  "details": [
    "string"
  ],
  "message": "string",
  "success": false
}

401 - object

Error Message

PropertyTypeRequiredDetails
detailsstring[]No-
messagestringNo-
successbooleanNo-

Generated example (synthetic):

{
  "details": [
    "string"
  ],
  "message": "string",
  "success": false
}

500 - object

Error Message

PropertyTypeRequiredDetails
detailsstring[]No-
messagestringNo-
successbooleanNo-

Generated example (synthetic):

{
  "details": [
    "string"
  ],
  "message": "string",
  "success": false
}

Contract identity

Use these fields to confirm you are implementing the intended endpoint contract.

  • API family: Auth API
  • Method: POST
  • Path: /api/v1/:app_id/auth/login
  • Operation ID: Not documented in the OpenAPI contract.
  • OpenAPI tag: Auth
  • OpenAPI summary: Login user

Login user

# Login user Authenticates a user and returns access token
POST /api/v1/:app_id/auth/login
Purpose

Authenticates a user and returns access token

Required inputs

app_id path

Primary response

200 ยท OK

Operation key

auth-api:POST:/api/v1/:app_id/auth/login

## API ownership - API family: Auth API - Best for: Customer identity, session, token, cart, and wishlist flows. - Do not use from: Merchant admin data syncs or public catalog rendering. - Guide route: [/apis/auth/latest](/apis/auth/latest) The OpenAPI contract defines the method, path, parameters, request body, and responses for this operation. ## Operation - Method: `POST` - Path: `/api/v1/:app_id/auth/login` - Summary: Login user - Description: Authenticates a user and returns access token - OpenAPI contract: auth-api - Operation ID: Not documented in the OpenAPI contract. - Stable operation key: `auth-api:POST:/api/v1/:app_id/auth/login` Operation key uses API family, method, and path because this OpenAPI contract does not publish an operation ID. ## Parameters | Name | In | Required | Type | Description | | --- | --- | --- | --- | --- | | app_id | path | Yes | string | UUID of the app | ## Request body - Required: Yes - Description: Login credentials - Content: application/json (object) ### Login Request | Property | Type | Required | Details | | --- | --- | --- | --- | | `email` | string | Yes | - | | `password` | string | Yes | minLength: 8 | **Generated example (synthetic):** ```json { "email": "string", "password": "string" } ``` ## Responses | Status | Description | Content | | --- | --- | --- | | 200 | OK | application/json (object) | | 400 | Invalid request | application/json (object) | | 401 | Invalid credentials | application/json (object) | | 500 | Internal server error | application/json (object) | ### 200 - object #### Login | Property | Type | Required | Details | | --- | --- | --- | --- | | `access_token` | string | No | - | | `expires_in` | integer | No | - | | `refresh_token` | string | No | - | | `token_type` | string | No | - | | `user` | object | No | - | ##### User | Property | Type | Required | Details | | --- | --- | --- | --- | | `additions` | object | No | - | | `address` | object | No | - | | `app_id` | string | No | - | | `attributes` | object[] | No | - | | `communication_preferences` | object | No | - | | `created_at` | string | No | - | | `customer_groups` | object[] | No | - | | `email` | string | No | - | | `email_verified` | boolean | No | - | | `files` | object[] | No | - | | `first_name` | string | No | - | | `id` | string | No | - | | `is_super_admin` | boolean | No | - | | `language` | string | No | - | | `last_login_at` | string | No | - | | `last_name` | string | No | - | | `market` | string | No | - | | `market_currency` | string | No | - | | `market_id` | string | No | - | | `organisations` | object[] | No | - | | `phone_number` | string | No | - | | `status` | string | No | - | | `store_group` | string | No | - | | `store_group_id` | string | No | - | | `tags` | object[] | No | - | | `updated_at` | string | No | - | ##### Address | Property | Type | Required | Details | | --- | --- | --- | --- | | `city` | string | No | - | | `country` | string | No | - | | `country_code` | string | No | - | | `street` | string | No | - | | `zip_code` | string | No | - | ##### Attribute | Property | Type | Required | Details | | --- | --- | --- | --- | | `description` | string | No | - | | `id` | string | No | - | | `key` | string | No | - | | `name` | string | No | - | | `template_key` | string | No | - | | `translations` | object | No | - | | `values` | object | No | - | ##### Communication Preferences | Property | Type | Required | Details | | --- | --- | --- | --- | | `allow_email` | boolean | No | - | | `allow_postal` | boolean | No | - | | `allow_sms` | boolean | No | - | ##### Customer Group Ref | Property | Type | Required | Details | | --- | --- | --- | --- | | `id` | string | No | - | | `name` | string | No | - | | `slug` | string | No | - | ##### File | Property | Type | Required | Details | | --- | --- | --- | --- | | `app_id` | string | No | - | | `content_type` | string | No | - | | `created_at` | string | No | - | | `custom_fields` | object | No | - | | `filename` | string | No | - | | `id` | string | No | - | | `updated_at` | string | No | - | | `url` | string | No | - | ##### Organisation With User Relation | Property | Type | Required | Details | | --- | --- | --- | --- | | `app_id` | string | No | - | | `attributes` | object[] | No | - | | `billing_address` | object[] | No | - | | `comment` | string | No | - | | `contact_name` | string | No | - | | `created_at` | string | No | - | | `credit_check` | boolean | No | - | | `custom_fields` | object | No | - | | `customer_groups` | object[] | No | - | | `email` | string | No | - | | `external_ref` | string | No | - | | `files` | object[] | No | - | | `id` | string | No | - | | `invoice_email` | string | No | - | | `level` | string | No | Can be null when a child organisation is without this user relation | | `name` | string | No | - | | `organisation_number` | string | No | - | | `parent_id` | string | No | - | | `phone` | string | No | - | | `role` | string | No | Can be null when a child organisation is without this user relation | | `role_name` | string | No | Can be null when a child organisation is without this user relation | | `shipping_address` | object[] | No | - | | `status` | string | No | - | | `store_groups` | object[] | No | - | | `tags` | object[] | No | - | | `tax_id_vat_number` | string | No | - | | `updated_at` | string | No | - | ##### Tag | Property | Type | Required | Details | | --- | --- | --- | --- | | `id` | string | No | - | | `key` | string | No | - | | `name` | string | No | - |
Generated example (synthetic) ```json { "access_token": "string", "expires_in": 0, "refresh_token": "string", "token_type": "string", "user": { "additions": {}, "address": { "city": "string", "country": "string", "country_code": "string", "street": "string", "zip_code": "string" }, "app_id": "string", "attributes": [ { "description": "string", "id": "string", "key": "string", "name": "string", "template_key": "string", "translations": { "description": null, "name": null }, "values": {} } ], "communication_preferences": { "allow_email": false, "allow_postal": false, "allow_sms": false }, "created_at": "string", "customer_groups": [ { "id": "string", "name": "string", "slug": "string" } ], "email": "string", "email_verified": false, "files": [ { "app_id": "string", "content_type": "string", "created_at": "string", "custom_fields": {}, "filename": "string", "id": "string", "updated_at": "string", "url": "string" } ], "first_name": "string", "id": "string", "is_super_admin": false, "language": "string", "last_login_at": "string", "last_name": "string", "market": "string", "market_currency": "string", "market_id": "string", "organisations": [ { "app_id": "string", "attributes": [], "billing_address": [], "comment": "string", "contact_name": "string", "created_at": "string", "credit_check": false, "custom_fields": {}, "customer_groups": [], "email": "string", "external_ref": "string", "files": [], "id": "string", "invoice_email": "string", "level": "string", "name": "string", "organisation_number": "string", "parent_id": "string", "phone": "string", "role": "string", "role_name": "string", "shipping_address": [], "status": "string", "store_groups": [], "tags": [], "tax_id_vat_number": "string", "updated_at": "string" } ], "phone_number": "string", "status": "string", "store_group": "string", "store_group_id": "string", "tags": [ { "id": "string", "key": "string", "name": "string" } ], "updated_at": "string" } } ```
### 400 - object #### Error Message | Property | Type | Required | Details | | --- | --- | --- | --- | | `details` | string[] | No | - | | `message` | string | No | - | | `success` | boolean | No | - | **Generated example (synthetic):** ```json { "details": [ "string" ], "message": "string", "success": false } ``` ### 401 - object #### Error Message | Property | Type | Required | Details | | --- | --- | --- | --- | | `details` | string[] | No | - | | `message` | string | No | - | | `success` | boolean | No | - | **Generated example (synthetic):** ```json { "details": [ "string" ], "message": "string", "success": false } ``` ### 500 - object #### Error Message | Property | Type | Required | Details | | --- | --- | --- | --- | | `details` | string[] | No | - | | `message` | string | No | - | | `success` | boolean | No | - | **Generated example (synthetic):** ```json { "details": [ "string" ], "message": "string", "success": false } ``` ## Contract identity Use these fields to confirm you are implementing the intended endpoint contract. - API family: Auth API - Method: `POST` - Path: `/api/v1/:app_id/auth/login` - Operation ID: Not documented in the OpenAPI contract. - Stable operation key: `auth-api:POST:/api/v1/:app_id/auth/login` - OpenAPI tag: Auth - OpenAPI summary: Login user