Use when: The user has an account and you need a bearer token, usually to create an API key.
Don't use when: You already have a working API key. Every data endpoint accepts the X-API-KEY header, so no login is needed.
Request body
Content type: application/json
| Field |
Type |
Required |
Description |
email |
string |
yes |
Account email. Example: user@example.com. |
password |
string |
yes |
Account password (plain — sent over TLS). Example: s3cret!. |
Notes for agents
- A
401 can mean wrong credentials, a disabled account, an IP address that isn't allowed, or an account that must sign in through SSO. Report the message to the user; do not loop on retries.
- Never store or repeat the password after this call.
- The valuation calls need an account with API access. Accounts created with
register have it. An existing account can still create a key, but if its valuation calls are refused, tell the user their account does not have API access.
Example request
curl -X POST https://app.smartcapitalcenter.com/api/v2/auth/login \
-H "Content-Type: application/json" \
-d '{"email": "user@example.com", "password": "s3cret!"}'
Response 200
Authentication successful — tokens issued.
{
"status": "success",
"data": {
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...signature",
"refresh_token": "def50200b8f1aA-9V0pQrSt...",
"expires_in": 900,
"token_type": "Bearer"
},
"message": null,
"code": null
}
Errors
| Code |
Meaning |
| 400 |
Validation error — missing or malformed fields |
| 401 |
Invalid credentials, disabled account, IP not allowed, or SSO-only login required |
Next: Call createApiKey, or use the bearer token wherever it is accepted.
# login
`POST /api/v2/auth/login`
Exchanges an email and password for a short-lived access token and a long-lived refresh token.
**Auth:** None
**Use when:** The user has an account and you need a bearer token, usually to create an API key.
**Don't use when:** You already have a working API key. Every data endpoint accepts the `X-API-KEY` header, so no login is needed.
## Request body
Content type: `application/json`
| Field | Type | Required | Description |
|---|---|---|---|
| `email` | string | yes | Account email. Example: `user@example.com`. |
| `password` | string | yes | Account password (plain — sent over TLS). Example: `s3cret!`. |
## Notes for agents
- A `401` can mean wrong credentials, a disabled account, an IP address that isn't allowed, or an account that must sign in through SSO. Report the `message` to the user; do not loop on retries.
- Never store or repeat the password after this call.
- The valuation calls need an account with API access. Accounts created with `register` have it. An existing account can still create a key, but if its valuation calls are refused, tell the user their account does not have API access.
## Example request
```bash
curl -X POST https://app.smartcapitalcenter.com/api/v2/auth/login \
-H "Content-Type: application/json" \
-d '{"email": "user@example.com", "password": "s3cret!"}'
```
## Response `200`
Authentication successful — tokens issued.
```json
{
"status": "success",
"data": {
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...signature",
"refresh_token": "def50200b8f1aA-9V0pQrSt...",
"expires_in": 900,
"token_type": "Bearer"
},
"message": null,
"code": null
}
```
## Errors
| Code | Meaning |
|---|---|
| 400 | Validation error — missing or malformed fields |
| 401 | Invalid credentials, disabled account, IP not allowed, or SSO-only login required |
**Next:** Call `createApiKey`, or use the bearer token wherever it is accepted.