SoftSolzSoftSolz
HomeAPI GuideAPI ReferenceWidget Tester
Customer Auth

Log an end-user in with email + password. Returns a session token, or an MFA challenge if 2FA is enabled.

Log an end-user in with email + password. Returns a session token, or an MFA challenge if 2FA is enabled.

POSThttps://app.softsolz.uk/api/v1/services/customer-auth/sessions

Recent Requests

Kept only in this browser
TimeStatusTook
Send a request with Try it to see it here.

Headers

Authorizationstringrequired

Bearer token: `Bearer sk_live_...` (or `sk_test_...` for sandbox). A login token will not work here.

Body Params

emailstringrequired

End-user email.

passwordstringrequired

End-user plaintext password.

Response

Response Body

userobjectEnd-user identity (non-MFA path).
sessionobjectThe issued session token and its metadata.
mfa_requiredbooleanPresent and true when an MFA challenge is required.
challenge_tokenstring | nullShort-lived (5 min) MFA challenge token (MFA path only).

Request

curl --request POST \
--url https://app.softsolz.uk/api/v1/services/customer-auth/sessions \
--header 'Authorization: Bearer sk_live_your_key' \
--header 'Content-Type: application/json' \
--data '{
"email": "user@example.com",
"password": "a-strong-passphrase"
}'

Credentials

Sent as a Bearer token and used in the samples above and in Try it. Kept only in this browser tab until you close it. Use an sk_test_ key to stay in your sandbox.

Response · 200

{
"data": {
"user": {
"id": "1042",
"email": "user@example.com"
},
"session": {
"token": "tok_example",
"jti": "11111111-1111-1111-1111-111111111111",
"issued_at": "2026-02-01T12:00:00.000Z",
"expires_at": "2026-02-08T12:00:00.000Z"
},
"mfa_required": false,
"challenge_token": "tok_example"
}
}