Smart Capital Center API reference

login

POST
/api/v2/auth/login

Exchanges an email and password for a short-lived access token and a long-lived refresh token.

Auth: None

Use when: The user has an account and you need a bearer token, usually to create an API key.

Don't use when: You already have a working API key. Every data endpoint accepts the X-API-KEY header, so no login is needed.

Request body

Content type: application/json

Field Type Required Description
email string yes Account email. Example: user@example.com.
password string yes Account password (plain — sent over TLS). Example: s3cret!.

Notes for agents

  • A 401 can mean wrong credentials, a disabled account, an IP address that isn't allowed, or an account that must sign in through SSO. Report the message to the user; do not loop on retries.
  • Never store or repeat the password after this call.
  • The valuation calls need an account with API access. Accounts created with register have it. An existing account can still create a key, but if its valuation calls are refused, tell the user their account does not have API access.

Example request

curl -X POST https://app.smartcapitalcenter.com/api/v2/auth/login \
  -H "Content-Type: application/json" \
  -d '{"email": "user@example.com", "password": "s3cret!"}'

Response 200

Authentication successful — tokens issued.

{
  "status": "success",
  "data": {
    "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...signature",
    "refresh_token": "def50200b8f1aA-9V0pQrSt...",
    "expires_in": 900,
    "token_type": "Bearer"
  },
  "message": null,
  "code": null
}

Errors

Code Meaning
400 Validation error — missing or malformed fields
401 Invalid credentials, disabled account, IP not allowed, or SSO-only login required

Next: Call createApiKey, or use the bearer token wherever it is accepted.

# login `POST /api/v2/auth/login` Exchanges an email and password for a short-lived access token and a long-lived refresh token. **Auth:** None **Use when:** The user has an account and you need a bearer token, usually to create an API key. **Don't use when:** You already have a working API key. Every data endpoint accepts the `X-API-KEY` header, so no login is needed. ## Request body Content type: `application/json` | Field | Type | Required | Description | |---|---|---|---| | `email` | string | yes | Account email. Example: `user@example.com`. | | `password` | string | yes | Account password (plain — sent over TLS). Example: `s3cret!`. | ## Notes for agents - A `401` can mean wrong credentials, a disabled account, an IP address that isn't allowed, or an account that must sign in through SSO. Report the `message` to the user; do not loop on retries. - Never store or repeat the password after this call. - The valuation calls need an account with API access. Accounts created with `register` have it. An existing account can still create a key, but if its valuation calls are refused, tell the user their account does not have API access. ## Example request ```bash curl -X POST https://app.smartcapitalcenter.com/api/v2/auth/login \ -H "Content-Type: application/json" \ -d '{"email": "user@example.com", "password": "s3cret!"}' ``` ## Response `200` Authentication successful — tokens issued. ```json { "status": "success", "data": { "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...signature", "refresh_token": "def50200b8f1aA-9V0pQrSt...", "expires_in": 900, "token_type": "Bearer" }, "message": null, "code": null } ``` ## Errors | Code | Meaning | |---|---| | 400 | Validation error — missing or malformed fields | | 401 | Invalid credentials, disabled account, IP not allowed, or SSO-only login required | **Next:** Call `createApiKey`, or use the bearer token wherever it is accepted.