Login user
Authenticates a user and returns access token
POST
/api/v1/:app_id/auth/login- API
- Auth
- OpenAPI
- auth-api
- Updated
- Apr 26, 2026
auth-api:POST:/api/v1/:app_id/auth/login
Authenticates a user and returns access token
API ownership
- API family: Auth API
- Best for: Customer identity, session, token, cart, and wishlist flows.
- Do not use from: Merchant admin data syncs or public catalog rendering.
- Guide route: /apis/auth/latest
The OpenAPI contract defines the method, path, parameters, request body, and responses for this operation.
Operation
- Method:
POST - Path:
/api/v1/:app_id/auth/login - Summary: Login user
- Description: Authenticates a user and returns access token
- OpenAPI contract: auth-api
- Operation ID: Not documented in the OpenAPI contract.
Operation key uses API family, method, and path because this OpenAPI contract does not publish an operation ID.
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
| app_id | path | Yes | string | UUID of the app |
Request body
- Required: Yes
- Description: Login credentials
- Content: application/json (object)
Login Request
| Property | Type | Required | Details |
|---|---|---|---|
email | string | Yes | - |
password | string | Yes | minLength: 8 |
Generated example (synthetic):
{
"email": "string",
"password": "string"
}Responses
| Status | Description | Content |
|---|---|---|
| 200 | OK | application/json (object) |
| 400 | Invalid request | application/json (object) |
| 401 | Invalid credentials | application/json (object) |
| 500 | Internal server error | application/json (object) |
200 - object
Login
| Property | Type | Required | Details |
|---|---|---|---|
access_token | string | No | - |
expires_in | integer | No | - |
refresh_token | string | No | - |
token_type | string | No | - |
user | object | No | - |
User
| Property | Type | Required | Details |
|---|---|---|---|
additions | object | No | - |
address | object | No | - |
app_id | string | No | - |
attributes | object[] | No | - |
communication_preferences | object | No | - |
created_at | string | No | - |
customer_groups | object[] | No | - |
email | string | No | - |
email_verified | boolean | No | - |
files | object[] | No | - |
first_name | string | No | - |
id | string | No | - |
is_super_admin | boolean | No | - |
language | string | No | - |
last_login_at | string | No | - |
last_name | string | No | - |
market | string | No | - |
market_currency | string | No | - |
market_id | string | No | - |
organisations | object[] | No | - |
phone_number | string | No | - |
status | string | No | - |
store_group | string | No | - |
store_group_id | string | No | - |
tags | object[] | No | - |
updated_at | string | No | - |
Address
| Property | Type | Required | Details |
|---|---|---|---|
city | string | No | - |
country | string | No | - |
country_code | string | No | - |
street | string | No | - |
zip_code | string | No | - |
Attribute
| Property | Type | Required | Details |
|---|---|---|---|
description | string | No | - |
id | string | No | - |
key | string | No | - |
name | string | No | - |
template_key | string | No | - |
translations | object | No | - |
values | object | No | - |
Communication Preferences
| Property | Type | Required | Details |
|---|---|---|---|
allow_email | boolean | No | - |
allow_postal | boolean | No | - |
allow_sms | boolean | No | - |
Customer Group Ref
| Property | Type | Required | Details |
|---|---|---|---|
id | string | No | - |
name | string | No | - |
slug | string | No | - |
File
| Property | Type | Required | Details |
|---|---|---|---|
app_id | string | No | - |
content_type | string | No | - |
created_at | string | No | - |
custom_fields | object | No | - |
filename | string | No | - |
id | string | No | - |
updated_at | string | No | - |
url | string | No | - |
Organisation With User Relation
| Property | Type | Required | Details |
|---|---|---|---|
app_id | string | No | - |
attributes | object[] | No | - |
billing_address | object[] | No | - |
comment | string | No | - |
contact_name | string | No | - |
created_at | string | No | - |
credit_check | boolean | No | - |
custom_fields | object | No | - |
customer_groups | object[] | No | - |
email | string | No | - |
external_ref | string | No | - |
files | object[] | No | - |
id | string | No | - |
invoice_email | string | No | - |
level | string | No | Can be null when a child organisation is without this user relation |
name | string | No | - |
organisation_number | string | No | - |
parent_id | string | No | - |
phone | string | No | - |
role | string | No | Can be null when a child organisation is without this user relation |
role_name | string | No | Can be null when a child organisation is without this user relation |
shipping_address | object[] | No | - |
status | string | No | - |
store_groups | object[] | No | - |
tags | object[] | No | - |
tax_id_vat_number | string | No | - |
updated_at | string | No | - |
Tag
| Property | Type | Required | Details |
|---|---|---|---|
id | string | No | - |
key | string | No | - |
name | string | No | - |
{
"access_token": "string",
"expires_in": 0,
"refresh_token": "string",
"token_type": "string",
"user": {
"additions": {},
"address": {
"city": "string",
"country": "string",
"country_code": "string",
"street": "string",
"zip_code": "string"
},
"app_id": "string",
"attributes": [
{
"description": "string",
"id": "string",
"key": "string",
"name": "string",
"template_key": "string",
"translations": {
"description": null,
"name": null
},
"values": {}
}
],
"communication_preferences": {
"allow_email": false,
"allow_postal": false,
"allow_sms": false
},
"created_at": "string",
"customer_groups": [
{
"id": "string",
"name": "string",
"slug": "string"
}
],
"email": "string",
"email_verified": false,
"files": [
{
"app_id": "string",
"content_type": "string",
"created_at": "string",
"custom_fields": {},
"filename": "string",
"id": "string",
"updated_at": "string",
"url": "string"
}
],
"first_name": "string",
"id": "string",
"is_super_admin": false,
"language": "string",
"last_login_at": "string",
"last_name": "string",
"market": "string",
"market_currency": "string",
"market_id": "string",
"organisations": [
{
"app_id": "string",
"attributes": [],
"billing_address": [],
"comment": "string",
"contact_name": "string",
"created_at": "string",
"credit_check": false,
"custom_fields": {},
"customer_groups": [],
"email": "string",
"external_ref": "string",
"files": [],
"id": "string",
"invoice_email": "string",
"level": "string",
"name": "string",
"organisation_number": "string",
"parent_id": "string",
"phone": "string",
"role": "string",
"role_name": "string",
"shipping_address": [],
"status": "string",
"store_groups": [],
"tags": [],
"tax_id_vat_number": "string",
"updated_at": "string"
}
],
"phone_number": "string",
"status": "string",
"store_group": "string",
"store_group_id": "string",
"tags": [
{
"id": "string",
"key": "string",
"name": "string"
}
],
"updated_at": "string"
}
}400 - object
Error Message
| Property | Type | Required | Details |
|---|---|---|---|
details | string[] | No | - |
message | string | No | - |
success | boolean | No | - |
Generated example (synthetic):
{
"details": [
"string"
],
"message": "string",
"success": false
}401 - object
Error Message
| Property | Type | Required | Details |
|---|---|---|---|
details | string[] | No | - |
message | string | No | - |
success | boolean | No | - |
Generated example (synthetic):
{
"details": [
"string"
],
"message": "string",
"success": false
}500 - object
Error Message
| Property | Type | Required | Details |
|---|---|---|---|
details | string[] | No | - |
message | string | No | - |
success | boolean | No | - |
Generated example (synthetic):
{
"details": [
"string"
],
"message": "string",
"success": false
}Contract identity
Use these fields to confirm you are implementing the intended endpoint contract.
- API family: Auth API
- Method:
POST - Path:
/api/v1/:app_id/auth/login - Operation ID: Not documented in the OpenAPI contract.
- OpenAPI tag: Auth
- OpenAPI summary: Login user