Authorization header of every request.
Log in
Send your email and password toPOST /v1/login/:
400.
Login is rate limited. Log in once and reuse the token until it expires,
instead of logging in before every request.
Send the token
Add the header to every request. The wordToken and the space after it are
required:
Token lifetime
A request with a missing, expired or revoked token returns
401. Log in again
to get a new token.
Two-factor authentication
If your account has two-factor authentication,POST /v1/login/ returns 202
with a challenge instead of a token:
challenge_id with the code from your authenticator app to
POST /v1/totp/login/:
Log out
POST /v1/logout/ revokes the token that made the request. Other tokens of
the same account stay valid.

