> ## Documentation Index
> Fetch the complete documentation index at: https://docs.glassmarkets.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Log in with your email and password, then send the token on every request.

The API uses token authentication. You log in once, receive a token, and send
it in the `Authorization` header of every request.

## Log in

Send your email and password to `POST /v1/login/`:

```bash theme={null}
curl -X POST https://api.glassmarkets.io/v1/login/ \
  -H "Content-Type: application/json" \
  -d '{"email": "you@example.com", "password": "your-password"}'
```

The response contains the token and the time it expires:

```json theme={null}
{
  "expiry": "2026-09-02T10:15:00Z",
  "token": "9944b09199c62bcf9418ad846dd0e4bbdfc6ee4b",
  "user": {
    "username": "you@example.com",
    "first_name": "Ada",
    "id": 42,
    "last_name": "Lovelace",
    "email": "you@example.com"
  }
}
```

A missing or wrong email or password returns `400`.

Login is rate limited. Log in once and reuse the token until it expires,
instead of logging in before every request.

## Send the token

Add the header to every request. The word `Token` and the space after it are
required:

```
Authorization: Token <token>
```

```bash theme={null}
curl https://api.glassmarkets.io/v1/organizations/ \
  -H "Authorization: Token <token>"
```

## Token lifetime

| Situation | The token is valid for |
| - | - |
| Default | 1 day after its last use |
| Logged in with `"remember_me": true` | At least 7 days |
| Any token | At most 30 days after login |

A request with a missing, expired or revoked token returns `401`. Log in again
to get a new token.

## Two-factor authentication

If your account has two-factor authentication, `POST /v1/login/` returns `202`
with a challenge instead of a token:

```json theme={null}
{
  "two_factor_required": true,
  "challenge_id": "..."
}
```

Send the `challenge_id` with the code from your authenticator app to
`POST /v1/totp/login/`:

```bash theme={null}
curl -X POST https://api.glassmarkets.io/v1/totp/login/ \
  -H "Content-Type: application/json" \
  -d '{"challenge_id": "...", "code": "123456"}'
```

The response is the same as a normal login.

## Log out

`POST /v1/logout/` revokes the token that made the request. Other tokens of
the same account stay valid.

```bash theme={null}
curl -X POST https://api.glassmarkets.io/v1/logout/ \
  -H "Authorization: Token <token>"
```
