Skip to main content
The API uses token authentication. You log in once, receive a token, and send it in the Authorization header of every request.

Log in

Send your email and password to POST /v1/login/:
The response contains the token and the time it expires:
A missing or wrong email or password returns 400. Login is rate limited. Log in once and reuse the token until it expires, instead of logging in before every request.

Send the token

Add the header to every request. The word Token and the space after it are required:

Token lifetime

A request with a missing, expired or revoked token returns 401. Log in again to get a new token.

Two-factor authentication

If your account has two-factor authentication, POST /v1/login/ returns 202 with a challenge instead of a token:
Send the challenge_id with the code from your authenticator app to POST /v1/totp/login/:
The response is the same as a normal login.

Log out

POST /v1/logout/ revokes the token that made the request. Other tokens of the same account stay valid.