Authenticate user and issue tokens
1 min
POST
https://api.upstartcommerce.com/api/v1/auth/login
acceptstringGenerated from available response content types
Authorizationstring<p>Guest token issued by <code>/api/v1/auth/guest</code>, carrying tenant (and site) context for the session.
The <code>tenant</code> claim is extracted and used as the active tenant for this login.
Falls back to <code>x-upstart-tenant</code> if absent or if the token cannot be parsed.</p>
x-upstart-tenantstring<p>Tenant identifier for multi-tenant authentication.</p>
<p>Required when user is authorized for multiple tenants.
Optional when user has exactly one authorized tenant (auto-selected).</p>
bodyobjectUser credentials for authentication
200<p>Authentication result. Either:</p>
<ul>
<li>Successful authentication with tokens (mfaRequired=false or absent)</li>
<li>MFA challenge required (mfaRequired=true)</li>
</ul>
400<p>Bad request - invalid JSON, missing fields, or tenant selection required</p>
401Invalid credentials
403<p>Forbidden - unauthorized tenant or no authorized tenants</p>
500Internal server error
curl --request POST \
--url https://api.upstartcommerce.com/api/v1/auth/login \
--header 'accept: application/json' \
--header 'content-type: application/json' \
--data-raw '{
"username": "[email protected]",
"password": "securePassword123",
"tokenType": "consumer"
}'