Authentication
Register, log in, and use the JWT you get back to authenticate every other request.
POST /api/auth/register
Creates a new user.
request
POST /api/auth/register
Content-Type: application/json
{
"name": "Ada Lovelace",
"email": "ada@example.com",
"password": "••••••••"
} response · 201
{
"user": {
"id": "usr_01h...",
"name": "Ada Lovelace",
"email": "ada@example.com"
},
"token": "eyJhbGciOi..."
}POST /api/auth/login
Exchanges credentials for a session token.
request
POST /api/auth/login
Content-Type: application/json
{
"email": "ada@example.com",
"password": "••••••••"
} response · 200
{
"token": "eyJhbGciOi...",
"expiresAt": "2026-08-15T00:00:00Z"
}Using the token
Send the token on every authenticated request as a bearer header:
request header
Authorization: Bearer eyJhbGciOi...
Tokens expireA token is valid until the Session's
expiresAt. A 401 response means the client should send the user back through login.