Log in and get a 30-day session JWT

posthttps://api.expiryedge.com/v1/login
Public - no API key10/15 minAny method
Request
curl -X POST 'https://api.expiryedge.com/v1/login' \
  -H "Content-Type: application/json" \
  -d '{
  "email": "priya.shah@northwinddental.com",
  "password": "Str0ng!Passw0rd"
}'
Response
{
  "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX2lkIjoidV83MWJYcSJ9.sig",
  "user": {
    "id": "u_71bXq",
    "email": "priya.shah@northwinddental.com",
    "displayName": "Priya Shah",
    "firstName": "Priya",
    "lastName": "Shah",
    "photoURL": null,
    "user_type": "organization",
    "organization_id": "org_northwind"
  },
  "teams": [
    {
      "id": "team_org_northwind_general",
      "name": "general",
      "role": "admin"
    }
  ]
}

Returns accessToken (HS256 session JWT, 30 days) to send as Authorization: Bearer. Errors use the legacy {message} shape. A Google sign-in for an email with no account auto-registers it and returns the register 201 response (no token) instead.

Body parameters

application/json
  • emailstringrequired
    format: email
  • passwordstring
    Account password. For login_type: google, may carry the Firebase ID token instead of idToken.
  • login_typestring
    Set to google to sign in with a Firebase ID token from Google sign-in.
    Allowedgoogle
  • idTokenstring
    Firebase ID token (Google sign-in). Its email must match email.
  • user_dataobject
    Optional Google profile hints used when a new account is auto-registered.

Returns

200
Credentials verified.
  • accessTokenstringrequiredread-only
    HS256 session JWT, valid 30 days. Send as Authorization: Bearer <accessToken>.
  • userobjectrequired
    A user profile (users/{uid}).
  • teamsarray of objectsrequired
    Teams the user belongs to.

Errors

201
Google sign-in for a new email - the account was registered (same body as register; no token).
401
Invalid email or password (also returned for a rejected Google ID token).
429
Too many requests for this endpoint from your IP. Wait Retry-After seconds.
500
Unexpected server error. Retry later; quote requestId to support.
503
Password verification is temporarily unavailable.