Skip to content

Login

POST
/v2/portal/auth/login
curl --request POST \
--url https://api.sipstack.com/v2/portal/auth/login \
--header 'Content-Type: application/json' \
--data '{ "email": "admin@acme.com", "password": "example", "remember": false }'

Authenticates a portal user and returns a session JWT (also set as an httpOnly portal_token cookie). Brute-force protected — see Rate Limits.

When the account has two-factor enabled, the response contains data.requiresMfa: true with a tempToken instead of a session — complete the login with POST /v2/portal/auth/2fa/login-verify.

Media type application/json
object
email
required
string format: email
Example
admin@acme.com
password
required
string format: password
remember

When true the session lasts 7 days instead of 8 hours.

boolean

Session created (or an MFA challenge when 2FA is enabled).

Media type application/json
object
success
boolean
data
object
token

Session JWT (also set as the httpOnly portal_token cookie).

string
user

The authenticated user, including role and organization context.

object
availableOrganizations

Organizations this account can act in (multi-org accounts).

Array<object>
object
requiresOrgSelection

When true, call POST /v2/portal/auth/switch-organization to scope the session.

boolean
requirePasswordChange
boolean
Example
{
"data": {
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOiI5YzFmMGEzZSIsIm9yZ0lkIjoiM2Y4ZTJkMWEifQ.7sQK0m1nH0qN0jV9pQ2rXk8cYt3wZb6uEaP1lLmS4dU",
"user": {
"id": "9c1f0a3e-2b4d-4c6e-8a10-5f7b9d0e1a2c",
"email": "admin@acme.com",
"firstName": "Alex",
"lastName": "Rivera",
"role": "admin",
"organizationId": "3f8e2d1a-9b7c-4e5f-a6d8-1c2b3a4f5e60"
},
"availableOrganizations": [
{
"id": "3f8e2d1a-9b7c-4e5f-a6d8-1c2b3a4f5e60",
"name": "Acme Inc"
}
],
"requiresOrgSelection": false,
"requirePasswordChange": false
}
}

Invalid credentials.

Media type application/json

Central error-handler shape used by most portal endpoints.

object
statusCode
integer
message
string
code

Machine-readable code, present when one applies. See Error Codes.

string
Example
{
"statusCode": 401,
"message": "Token expired",
"code": "TOKEN_EXPIRED"
}

Organization suspended (code: ORG_SUSPENDED).

Too many attempts for this email or IP.