Log in and get a 30-day session JWT
post
https://api.expiryedge.com/v1/loginÖffentlich - kein API-Schlüssel10/15 minJede Methode
Anfrage
curl -X POST 'https://api.expiryedge.com/v1/login' \
-H "Content-Type: application/json" \
-d '{
"email": "priya.shah@northwinddental.com",
"password": "Str0ng!Passw0rd"
}'Antwort
{
"accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX2lkIjoidV83MWJYcSJ9.sig",
"user": {
"id": "u_71bXq",
"email": "priya.shah@northwinddental.com",
"displayName": "Priya Shah",
"firstName": "Priya",
"lastName": "Shah",
"photoURL": null,
"user_type": "organization",
"organization_id": "org_northwind"
},
"teams": [
{
"id": "team_org_northwind_general",
"name": "general",
"role": "admin"
}
]
}Returns accessToken (HS256 session JWT, 30 days) to send as Authorization: Bearer.
Errors use the legacy {message} shape. A Google sign-in for an email with no account auto-registers
it and returns the register 201 response (no token) instead.
emailstringerforderlichformat: emailpasswordstringAccount password. Forlogin_type: google, may carry the Firebase ID token instead ofidToken.login_typestringSet togoogleto sign in with a Firebase ID token from Google sign-in.ErlaubtgoogleidTokenstringFirebase ID token (Google sign-in). Its email must matchemail.user_dataobjectOptional Google profile hints used when a new account is auto-registered.
200
Credentials verified.
accessTokenstringerforderlichschreibgeschütztHS256 session JWT, valid 30 days. Send asAuthorization: Bearer <accessToken>.userobjecterforderlichA user profile (users/{uid}).teamsarray of objectserforderlichTeams the user belongs to.
201 | Google sign-in for a new email - the account was registered (same body as register; no token). |
401 | Invalid email or password (also returned for a rejected Google ID token). |
429 | Too many requests for this endpoint from your IP. Wait Retry-After seconds. |
500 | Unexpected server error. Retry later; quote requestId to support. |
503 | Password verification is temporarily unavailable. |
