Login
curl --request POST \ --url https://api.sipstack.com/v2/portal/auth/login \ --header 'Content-Type: application/json' \ --data '{ "email": "admin@acme.com", "password": "example", "remember": false }'import requests
url = "https://api.sipstack.com/v2/portal/auth/login"
payload = { "email": "admin@acme.com", "password": "example", "remember": False}headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.json())const url = 'https://api.sipstack.com/v2/portal/auth/login';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"email":"admin@acme.com","password":"example","remember":false}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}import axios from 'axios';
const options = { method: 'POST', url: 'https://api.sipstack.com/v2/portal/auth/login', headers: {'Content-Type': 'application/json'}, data: {email: 'admin@acme.com', password: 'example', remember: false}};
try { const { data } = await axios.request(options); console.log(data);} catch (error) { console.error(error);}Authenticates a portal user and returns a session JWT (also set as an
httpOnly portal_token cookie). Brute-force protected — see
Rate Limits.
When the account has two-factor enabled, the response contains
data.requiresMfa: true with a tempToken instead of a session —
complete the login with POST /v2/portal/auth/2fa/login-verify.
Request Body required
Section titled “Request Body required ”object
Example
admin@acme.comWhen true the session lasts 7 days instead of 8 hours.
Responses
Section titled “ Responses ”Session created (or an MFA challenge when 2FA is enabled).
object
object
Session JWT (also set as the httpOnly portal_token cookie).
The authenticated user, including role and organization context.
object
Organizations this account can act in (multi-org accounts).
object
When true, call POST /v2/portal/auth/switch-organization to scope the session.
Example
{ "data": { "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOiI5YzFmMGEzZSIsIm9yZ0lkIjoiM2Y4ZTJkMWEifQ.7sQK0m1nH0qN0jV9pQ2rXk8cYt3wZb6uEaP1lLmS4dU", "user": { "id": "9c1f0a3e-2b4d-4c6e-8a10-5f7b9d0e1a2c", "email": "admin@acme.com", "firstName": "Alex", "lastName": "Rivera", "role": "admin", "organizationId": "3f8e2d1a-9b7c-4e5f-a6d8-1c2b3a4f5e60" }, "availableOrganizations": [ { "id": "3f8e2d1a-9b7c-4e5f-a6d8-1c2b3a4f5e60", "name": "Acme Inc" } ], "requiresOrgSelection": false, "requirePasswordChange": false }}Invalid credentials.
Central error-handler shape used by most portal endpoints.
object
Machine-readable code, present when one applies. See Error Codes.
Example
{ "statusCode": 401, "message": "Token expired", "code": "TOKEN_EXPIRED"}Organization suspended (code: ORG_SUSPENDED).
Too many attempts for this email or IP.