API overview
Create a named API token
Choose an operation to see its request, response shape, access rules and implementation source.
WriteEmail + password
POST/api/v1/auth/tokens
Create a named API token
No auth:sanctum or bearer ability is required by this route.
Request
| Field | In | Rule |
|---|---|---|
email | JSON body | Required valid email address. |
password | JSON body | Required string. Never submit credentials to this documentation site. |
name | JSON body | Required string; max 80. |
abilities | JSON body | Optional array, max 50 allowed ability strings. Omission grants full access; choose explicit least-privilege abilities. |
curl --request POST "https://shop.example.test/api/v1/auth/tokens" \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data '{"email":"[email protected]","password":"<password>","name":"Documentation example","abilities":["account.read"]}'Response201
Success: 201
Response shape (notation, not a captured response)
{ token: string, token_type: "Bearer", name: string }Common errors
| HTTP status | Meaning |
|---|---|
403 | unauthorized, insufficient_scope or ip_not_allowed: check account context, required ability and token IP policy. |
422 | validation_error: invalid input or unmet domain requirements. Payment initiation can also return payment_failed. |
429 | rate_limited: back off before retrying, especially writes. |