Skip to content

Auth - User ​

Base URL: https://your-domain.com

Authentication endpoints for Admin/Staff/Reseller users. Login returns a Bearer token; use Refresh Token to renew it without re-sending credentials.

API token rules — read before you integrate

  • Lifetime: 30 days from login or refresh (server-configurable with API_USER_TOKEN_DAYS). The exact moment is in data.expires_at (server time).
  • Refreshing rotates the token. POST /api/v1/users/refresh-token returns a new token and the old one stops working at once — overwrite what you stored.
  • A token is revoked before expires_at when:
    • the user account is disabled (status ≠ 1),
    • the user's password is changed — by the user or by an admin — every token of that user is deleted,
    • Logout / Logout All Devices is called.
  • An expired or revoked token cannot be refreshed — the request gets 401 Unauthenticated.. Log in again; treat 401 as "get a new token", never as a bug.
  • Login is rate-limited to 5 attempts per minute per username + IP — cache the token, don't log in per request.

New to the API?

The Quickstart walks through login, token renewal and creating a subscriber with a complete client in PHP, JavaScript, Python, Go and Rust.


Login ​

Authenticate a user (Admin/Staff/Reseller) and receive an access token for API access. The email field accepts either the user's email address or username.

PropertyValue
EndpointUser Login
MethodPOST
URL/api/v1/users/login
AuthenticationNot Required
Legacy alias

POST /api/auth-login accepts the same body and returns the same response. New integrations should use /api/v1/users/login.

Request Headers:

HeaderValueRequired
Content-Typeapplication/jsonYes
Acceptapplication/jsonYes

Request Body:

json
{
    "email": "[email protected]",
    "password": "your-password"
}
ParameterTypeRequiredDescription
emailstringYesUser's email address or username
passwordstringYesUser's password

Success Response (200 OK):

json
{
    "status": "success",
    "message": "Login Successful",
    "data": {
        "user": {
            "id": 1,
            "name": "Admin User",
            "email": "[email protected]",
            "profile_type": 1,
            "isp_id": 1,
            "branch_id": 1
        },
        "token": "12|k3jH8sDf9aLpQwErTyUiOp1234567890abcdef",
        "token_type": "Bearer",
        "expires_at": "2025-01-02 10:30:00"
    }
}
FieldDescription
data.tokenBearer token — send it in the Authorization header on every protected request
data.expires_atServer time (Y-m-d H:i:s) when the token stops working — 30 days after login by default
data.user.profile_type1 = Admin. Other profile types need the api_access permission
data.user.isp_id, data.user.branch_idPass these as isp_id / branch_id on multi-tenant endpoints

Error Response (401 Unauthorized):

json
{
    "status": "error",
    "message": "Invalid Username Or Email Or Password"
}

Error Response (403 Forbidden):

json
{
    "status": "error",
    "message": "You Do Not Have Permission To Access The API. Please Contact Administrator."
}

Also returned with "Your Account Is Not Active. Please Contact Administrator." when the user is disabled.

Error Response (422 Validation Error):

json
{
    "status": "error",
    "message": "Validation Failed",
    "errors": {
        "email": ["The email field is required."],
        "password": ["The password field is required."]
    }
}

Error Response (429 Too Many Requests):

Login is rate-limited to 5 attempts per minute per username + IP.

Code Examples:

bash
curl -X POST "https://your-domain.com/api/v1/users/login" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "[email protected]",
    "password": "your-password"
  }'
php
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client(['base_uri' => 'https://your-domain.com']);

$response = $client->request('POST', '/api/v1/users/login', [
    'headers' => [
        'Accept'        => 'application/json',
    ],
    'json' => [
        'email'    => '[email protected]',
        'password' => 'your-password',
    ],
]);

$data = json_decode($response->getBody(), true);
print_r($data);
javascript
const BASE_URL = 'https://your-domain.com';

const response = await fetch(`${BASE_URL}/api/v1/users/login`, {
  method: 'POST',
  headers: {
    Accept: 'application/json',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    email: '[email protected]',
    password: 'your-password',
  }),
});

const data = await response.json();
console.log(data);
python
import requests

BASE_URL = "https://your-domain.com"

response = requests.post(
    f"{BASE_URL}/api/v1/users/login",
    headers={
        "Accept": "application/json",
    },
    json={
        "email": "[email protected]",
        "password": "your-password",
    },
)

data = response.json()
print(data)
go
package main

import (
	"bytes"
	"encoding/json"
	"fmt"
	"io"
	"net/http"
)

const baseURL = "https://your-domain.com"

func main() {
	endpoint := baseURL + "/api/v1/users/login"

	payload, _ := json.Marshal(map[string]any{
		"email":    "[email protected]",
		"password": "your-password",
	})
	req, _ := http.NewRequest("POST", endpoint, bytes.NewBuffer(payload))
	req.Header.Set("Accept", "application/json")
	req.Header.Set("Content-Type", "application/json")

	resp, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()

	body, _ := io.ReadAll(resp.Body)
	fmt.Println(resp.StatusCode, string(body))
}
rust
use reqwest::Client;
use serde_json::json;

const BASE_URL: &str = "https://your-domain.com";

#[tokio::main]
async fn main() -> Result<(), reqwest::Error> {
    let client = Client::new();

    let response = client
        .post(format!("{BASE_URL}/api/v1/users/login"))
        .header("Accept", "application/json")
        .json(&json!({
            "email": "[email protected]",
            "password": "your-password"
        }))
        .send()
        .await?;

    let data: serde_json::Value = response.json().await?;
    println!("{data:#}");
    Ok(())
}

Profile (Get Current User) ​

Retrieve the authenticated user's profile. Useful to verify a stored token is still valid.

PropertyValue
EndpointGet Current User
MethodGET
URL/api/v1/users/profile
AuthenticationBearer Token

Request Headers:

HeaderValueRequired
Acceptapplication/jsonYes
AuthorizationBearer your-auth-tokenYes

Request Body: None

Success Response (200 OK):

json
{
    "status": "success",
    "data": {
        "user": {
            "id": 1,
            "name": "Admin User",
            "username": "admin",
            "email": "[email protected]",
            "phone": "01712345678",
            "profile_type": 1,
            "isp_id": 1,
            "branch_id": 1,
            "status": 1
        }
    }
}

Error Response (401 Unauthorized):

json
{
    "message": "Unauthenticated."
}

Code Examples:

bash
curl -X GET "https://your-domain.com/api/v1/users/profile" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer your-auth-token"
php
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client(['base_uri' => 'https://your-domain.com']);

$response = $client->request('GET', '/api/v1/users/profile', [
    'headers' => [
        'Accept'        => 'application/json',
        'Authorization' => 'Bearer your-auth-token',
    ],
]);

$data = json_decode($response->getBody(), true);
print_r($data);
javascript
const BASE_URL = 'https://your-domain.com';
const TOKEN = 'your-auth-token';

const response = await fetch(`${BASE_URL}/api/v1/users/profile`, {
  method: 'GET',
  headers: {
    Accept: 'application/json',
    Authorization: `Bearer ${TOKEN}`,
  },
});

const data = await response.json();
console.log(data);
python
import requests

BASE_URL = "https://your-domain.com"
TOKEN = "your-auth-token"

response = requests.get(
    f"{BASE_URL}/api/v1/users/profile",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {TOKEN}",
    },
)

data = response.json()
print(data)
go
package main

import (
	"fmt"
	"io"
	"net/http"
)

const baseURL = "https://your-domain.com"
const token = "your-auth-token"

func main() {
	endpoint := baseURL + "/api/v1/users/profile"

	req, _ := http.NewRequest("GET", endpoint, nil)
	req.Header.Set("Accept", "application/json")
	req.Header.Set("Authorization", "Bearer "+token)

	resp, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()

	body, _ := io.ReadAll(resp.Body)
	fmt.Println(resp.StatusCode, string(body))
}
rust
use reqwest::Client;

const BASE_URL: &str = "https://your-domain.com";
const TOKEN: &str = "your-auth-token";

#[tokio::main]
async fn main() -> Result<(), reqwest::Error> {
    let client = Client::new();

    let response = client
        .get(format!("{BASE_URL}/api/v1/users/profile"))
        .header("Accept", "application/json")
        .bearer_auth(TOKEN)
        .send()
        .await?;

    let data: serde_json::Value = response.json().await?;
    println!("{data:#}");
    Ok(())
}

Refresh Token ​

Exchange the current token for a new one with a fresh full lifetime (30 days by default). The old token is revoked immediately, so replace the stored token with the new one from the response.

Call this shortly before expires_at (for example when less than a day is left). If the token has already expired the request fails with 401 — log in again instead.

PropertyValue
EndpointRefresh Token
MethodPOST
URL/api/v1/users/refresh-token
AuthenticationBearer Token

Request Headers:

HeaderValueRequired
Acceptapplication/jsonYes
AuthorizationBearer your-auth-tokenYes

Request Body: None

Success Response (200 OK):

json
{
    "status": "success",
    "message": "Token Refreshed Successfully",
    "data": {
        "token": "13|Zx9cVbNm7QwErTyUiOp0987654321fedcba",
        "token_type": "Bearer",
        "expires_at": "2025-01-03 10:30:00"
    }
}

Error Response (401 Unauthorized):

json
{
    "message": "Unauthenticated."
}

Returned when the token is invalid, revoked or already expired. Log in again to get a new token.

Code Examples:

bash
curl -X POST "https://your-domain.com/api/v1/users/refresh-token" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer your-auth-token"
php
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client(['base_uri' => 'https://your-domain.com']);

$response = $client->request('POST', '/api/v1/users/refresh-token', [
    'headers' => [
        'Accept'        => 'application/json',
        'Authorization' => 'Bearer your-auth-token',
    ],
]);

$data = json_decode($response->getBody(), true);
print_r($data);
javascript
const BASE_URL = 'https://your-domain.com';
const TOKEN = 'your-auth-token';

const response = await fetch(`${BASE_URL}/api/v1/users/refresh-token`, {
  method: 'POST',
  headers: {
    Accept: 'application/json',
    Authorization: `Bearer ${TOKEN}`,
  },
});

const data = await response.json();
console.log(data);
python
import requests

BASE_URL = "https://your-domain.com"
TOKEN = "your-auth-token"

response = requests.post(
    f"{BASE_URL}/api/v1/users/refresh-token",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {TOKEN}",
    },
)

data = response.json()
print(data)
go
package main

import (
	"fmt"
	"io"
	"net/http"
)

const baseURL = "https://your-domain.com"
const token = "your-auth-token"

func main() {
	endpoint := baseURL + "/api/v1/users/refresh-token"

	req, _ := http.NewRequest("POST", endpoint, nil)
	req.Header.Set("Accept", "application/json")
	req.Header.Set("Authorization", "Bearer "+token)

	resp, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()

	body, _ := io.ReadAll(resp.Body)
	fmt.Println(resp.StatusCode, string(body))
}
rust
use reqwest::Client;

const BASE_URL: &str = "https://your-domain.com";
const TOKEN: &str = "your-auth-token";

#[tokio::main]
async fn main() -> Result<(), reqwest::Error> {
    let client = Client::new();

    let response = client
        .post(format!("{BASE_URL}/api/v1/users/refresh-token"))
        .header("Accept", "application/json")
        .bearer_auth(TOKEN)
        .send()
        .await?;

    let data: serde_json::Value = response.json().await?;
    println!("{data:#}");
    Ok(())
}

Logout ​

Revoke the current token. Other tokens for the same user (e.g. another device) keep working.

PropertyValue
EndpointUser Logout
MethodPOST
URL/api/v1/users/logout
AuthenticationBearer Token

Request Headers:

HeaderValueRequired
Acceptapplication/jsonYes
AuthorizationBearer your-auth-tokenYes

Request Body: None

Success Response (200 OK):

json
{
    "status": "success",
    "message": "Logged Out Successfully"
}

Error Response (401 Unauthorized):

json
{
    "message": "Unauthenticated."
}

Code Examples:

bash
curl -X POST "https://your-domain.com/api/v1/users/logout" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer your-auth-token"
php
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client(['base_uri' => 'https://your-domain.com']);

$response = $client->request('POST', '/api/v1/users/logout', [
    'headers' => [
        'Accept'        => 'application/json',
        'Authorization' => 'Bearer your-auth-token',
    ],
]);

$data = json_decode($response->getBody(), true);
print_r($data);
javascript
const BASE_URL = 'https://your-domain.com';
const TOKEN = 'your-auth-token';

const response = await fetch(`${BASE_URL}/api/v1/users/logout`, {
  method: 'POST',
  headers: {
    Accept: 'application/json',
    Authorization: `Bearer ${TOKEN}`,
  },
});

const data = await response.json();
console.log(data);
python
import requests

BASE_URL = "https://your-domain.com"
TOKEN = "your-auth-token"

response = requests.post(
    f"{BASE_URL}/api/v1/users/logout",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {TOKEN}",
    },
)

data = response.json()
print(data)
go
package main

import (
	"fmt"
	"io"
	"net/http"
)

const baseURL = "https://your-domain.com"
const token = "your-auth-token"

func main() {
	endpoint := baseURL + "/api/v1/users/logout"

	req, _ := http.NewRequest("POST", endpoint, nil)
	req.Header.Set("Accept", "application/json")
	req.Header.Set("Authorization", "Bearer "+token)

	resp, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()

	body, _ := io.ReadAll(resp.Body)
	fmt.Println(resp.StatusCode, string(body))
}
rust
use reqwest::Client;

const BASE_URL: &str = "https://your-domain.com";
const TOKEN: &str = "your-auth-token";

#[tokio::main]
async fn main() -> Result<(), reqwest::Error> {
    let client = Client::new();

    let response = client
        .post(format!("{BASE_URL}/api/v1/users/logout"))
        .header("Accept", "application/json")
        .bearer_auth(TOKEN)
        .send()
        .await?;

    let data: serde_json::Value = response.json().await?;
    println!("{data:#}");
    Ok(())
}

Logout All Devices ​

Revoke every token issued to the current user.

PropertyValue
EndpointUser Logout All
MethodPOST
URL/api/v1/users/logout-all
AuthenticationBearer Token

Request Headers:

HeaderValueRequired
Acceptapplication/jsonYes
AuthorizationBearer your-auth-tokenYes

Request Body: None

Success Response (200 OK):

json
{
    "status": "success",
    "message": "Logged Out From All Devices Successfully"
}

Code Examples:

bash
curl -X POST "https://your-domain.com/api/v1/users/logout-all" \
  -H "Accept: application/json" \
  -H "Authorization: Bearer your-auth-token"
php
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client(['base_uri' => 'https://your-domain.com']);

$response = $client->request('POST', '/api/v1/users/logout-all', [
    'headers' => [
        'Accept'        => 'application/json',
        'Authorization' => 'Bearer your-auth-token',
    ],
]);

$data = json_decode($response->getBody(), true);
print_r($data);
javascript
const BASE_URL = 'https://your-domain.com';
const TOKEN = 'your-auth-token';

const response = await fetch(`${BASE_URL}/api/v1/users/logout-all`, {
  method: 'POST',
  headers: {
    Accept: 'application/json',
    Authorization: `Bearer ${TOKEN}`,
  },
});

const data = await response.json();
console.log(data);
python
import requests

BASE_URL = "https://your-domain.com"
TOKEN = "your-auth-token"

response = requests.post(
    f"{BASE_URL}/api/v1/users/logout-all",
    headers={
        "Accept": "application/json",
        "Authorization": f"Bearer {TOKEN}",
    },
)

data = response.json()
print(data)
go
package main

import (
	"fmt"
	"io"
	"net/http"
)

const baseURL = "https://your-domain.com"
const token = "your-auth-token"

func main() {
	endpoint := baseURL + "/api/v1/users/logout-all"

	req, _ := http.NewRequest("POST", endpoint, nil)
	req.Header.Set("Accept", "application/json")
	req.Header.Set("Authorization", "Bearer "+token)

	resp, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer resp.Body.Close()

	body, _ := io.ReadAll(resp.Body)
	fmt.Println(resp.StatusCode, string(body))
}
rust
use reqwest::Client;

const BASE_URL: &str = "https://your-domain.com";
const TOKEN: &str = "your-auth-token";

#[tokio::main]
async fn main() -> Result<(), reqwest::Error> {
    let client = Client::new();

    let response = client
        .post(format!("{BASE_URL}/api/v1/users/logout-all"))
        .header("Accept", "application/json")
        .bearer_auth(TOKEN)
        .send()
        .await?;

    let data: serde_json::Value = response.json().await?;
    println!("{data:#}");
    Ok(())
}

www.onezeroart.com