Sign in
POST/auth/login
No token. One of the calls you make before you have one. Send X-Tenant-Code where the operation lists it — that is which tenant you are asking about, not proof of who you are.
Exchanges an email and password for an access token, in the tenant named by X-Tenant-Code.
Which population the email is looked up in follows from the host the request came from: a consumer host resolves to wallet holders, an operator host to staff. The access token is
short-lived; the refresh token comes back as an HttpOnly cookie for browsers, or in the response body for native clients that send X-Client: mobile.
A wrong email and a wrong password fail identically, on purpose — the response cannot be used to discover whether an account exists.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 409
- 422
- 500
OK
Malformed request — validation failure, or a header such as Idempotency-Key is missing or not a UUID.
Missing, expired, or untrusted bearer token.
Authenticated but not permitted — the caller's role or scope does not grant this operation, or the resource belongs to another tenant.
The referenced wallet, transaction, user, or tenant does not exist within the caller's tenant.
Idempotency conflict — a request with this Idempotency-Key is still in flight. Retry once it settles. A key belonging to an already-completed request is NOT an error: the original response is replayed with its original status.
The request is well-formed but violates a business rule — for example a posting that would breach a wallet fund's balance floor, a transaction type not enabled for the tenant, a per-transaction or daily issuance cap, or an operation on a frozen wallet.
Unexpected server error.