Log an end-user in with email + password. Returns a session token, or an MFA challenge if 2FA is enabled.
Log an end-user in with email + password. Returns a session token, or an MFA challenge if 2FA is enabled.
POST
https://app.softsolz.uk/api/v1/services/customer-auth/sessionsRecent Requests
Kept only in this browserTimeStatusTook
Send a request with Try it to see it here.
Headers
AuthorizationstringrequiredBearer token: `Bearer sk_live_...` (or `sk_test_...` for sandbox). A login token will not work here.
Body Params
emailstringrequiredEnd-user email.
passwordstringrequiredEnd-user plaintext password.
Response
Response Body
userobjectEnd-user identity (non-MFA path).sessionobjectThe issued session token and its metadata.mfa_requiredbooleanPresent and true when an MFA challenge is required.challenge_tokenstring | nullShort-lived (5 min) MFA challenge token (MFA path only).Request
curl --request POST \ --url https://app.softsolz.uk/api/v1/services/customer-auth/sessions \ --header 'Authorization: Bearer sk_live_your_key' \ --header 'Content-Type: application/json' \ --data '{ "email": "user@example.com", "password": "a-strong-passphrase"}'Credentials
Sent as a Bearer token and used in the samples above and in Try it. Kept only in this browser tab until you close it. Use an sk_test_ key to stay in your sandbox.
Response · 200
{ "data": { "user": { "id": "1042", "email": "user@example.com" }, "session": { "token": "tok_example", "jti": "11111111-1111-1111-1111-111111111111", "issued_at": "2026-02-01T12:00:00.000Z", "expires_at": "2026-02-08T12:00:00.000Z" }, "mfa_required": false, "challenge_token": "tok_example" }}