Skip to main content

Login

Authenticate a user and obtain a JWT token for subsequent API requests.

POST/apidev/v1/login
PermissionNone (public)
Rate Limit5 req/30s per account
CacheNone

Overview​

Authenticates a user by email and password and returns a signed JWT token valid for 1 hour. This is a public endpoint — no JWT or API Key required, only the tenant header.

For the full dual-auth model (JWT + API Key) and how to use the token on protected endpoints, see Authentication.


Request​

Headers​

HeaderTypeRequiredDescription
tenantstringYesYour assigned tenant domain (default: geotareas.com) — always send your assigned tenant
Content-TypestringYesMust be application/json

Body Parameters​

ParameterTypeRequiredDescription
emailstringYesUser email address
passwordstringYesUser password
playeridstringNoPush-notification player id to register for this user (max 300)

Code Examples​

curl -X POST "https://$TENANT/apidev/v1/login" \
-H "tenant: $TENANT" \
-H "Content-Type: application/json" \
-d '{
"email": "dev@company.com",
"password": "your_password"
}'

Response​

Success — 200 OK​

FieldTypeDescription
successbooleanAlways true on success
data.authorizationobjectWrapper object — the token is nested inside
data.authorization.tokenstringSigned JWT token, valid for 1 hour. This is the value you send as Authorization: Bearer <token>
metaobjectEmpty object
The token is nested

Read the JWT from data.authorization.token, not from data.authorization. Sending the wrapper object as your Bearer credential makes every subsequent call fail with 401 UNAUTHORIZED — with no hint that the token was the problem.

{
"success": true,
"data": {
"authorization": { "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." }
},
"meta": {}
}

Errors​

HTTP CodeError CodeCause
400VALIDATION_ERRORMissing or malformed body (e.g. invalid email format, missing password)
401UNAUTHORIZEDMissing tenant header, or invalid email or password
401TOKEN_EXPIREDA previously issued JWT is valid but has passed its 1-hour lifetime
403COMPANY_SUSPENDEDThe company account is suspended — no tokens are issued and every API endpoint returns this code until the account is reactivated. Contact Logicsat support
429RATE_LIMITED5+ failed attempts in 30s — account blocked for 60 seconds
{
"success": false,
"data": null,
"error": {
"code": "UNAUTHORIZED",
"message": "Invalid email or password."
}
}

Next steps​

Once you have the token, attach it alongside your API Key and tenant header on every request. See Using the Token for the exact headers required.