Auth
Call once before the first POST from a fresh browser (any response sets the cookie when it is missing).
Cookie set
curl -X GET "https://example.com/auth/csrf"Providers
application/json- response
providers*array<>curl -X GET "https://example.com/auth/providers"{ "providers": [ "google" ]}application/json- body
email*stringemaillength <= 254password*string10 <= length <= 128name*string1 <= length <= 100Account created and signed in; a verification email was sent.
application/json- response
user*organizations*array<>mfa_required*booleanTrue while the session still needs a second factor; other endpoints return 401 mfa_required.
curl -X POST "https://example.com/auth/signup" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]", "password": "stringstri", "name": "string" }'{ "user": { "id": 0, "email": "string", "name": "string", "locale": "string", "email_verified": true, "mfa_enabled": true, "has_password": true, "created": "2019-08-24T14:15:22Z" }, "organizations": [ { "id": 0, "name": "string", "kind": "personal", "role": "owner", "status": "active" } ], "mfa_required": true}application/json- body
email*stringemailpassword*stringSigned in. If mfa_required is true, call /auth/mfa/totp next.
application/json- response
user*organizations*array<>mfa_required*booleanTrue while the session still needs a second factor; other endpoints return 401 mfa_required.
curl -X POST "https://example.com/auth/login" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]", "password": "string" }'{ "user": { "id": 0, "email": "string", "name": "string", "locale": "string", "email_verified": true, "mfa_enabled": true, "has_password": true, "created": "2019-08-24T14:15:22Z" }, "organizations": [ { "id": 0, "name": "string", "kind": "personal", "role": "owner", "status": "active" } ], "mfa_required": true}cookieAuthodx_session<token>application/json- body
code*string6-digit TOTP code or a recovery code
Session is now fully authenticated.
application/json- response
user*organizations*array<>mfa_required*booleanTrue while the session still needs a second factor; other endpoints return 401 mfa_required.
curl -X POST "https://example.com/auth/mfa/totp" \ -H "Content-Type: application/json" \ -d '{ "code": "string" }'{ "user": { "id": 0, "email": "string", "name": "string", "locale": "string", "email_verified": true, "mfa_enabled": true, "has_password": true, "created": "2019-08-24T14:15:22Z" }, "organizations": [ { "id": 0, "name": "string", "kind": "personal", "role": "owner", "status": "active" } ], "mfa_required": true}cookieAuthodx_session<token>Signed out
curl -X POST "https://example.com/auth/logout"application/json- body
token*stringEmail verified
curl -X POST "https://example.com/auth/verify-email" \ -H "Content-Type: application/json" \ -d '{ "token": "string" }'cookieAuthodx_session<token>Sent (rate limited)
curl -X POST "https://example.com/auth/verify-email/resend"Always returns 204, whether or not the address exists.
application/json- body
email*stringemailAccepted
curl -X POST "https://example.com/auth/password/forgot" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]" }'Revokes all existing sessions of the user.
application/json- body
token*stringpassword*string10 <= length <= 128Password changed
curl -X POST "https://example.com/auth/password/reset" \ -H "Content-Type: application/json" \ -d '{ "token": "string", "password": "stringstri" }'provider*string"google""github"Redirect to the provider
curl -X GET "https://example.com/auth/oauth/google/start"provider*string"google""github"code?stringstate?stringerror?stringRedirect to the console
curl -X GET "https://example.com/auth/oauth/google/callback"