merchant_token cookie. The cookie lasts 7 days and is required for the dashboard endpoints documented in this group — /me, /wallet, and /withdraw. To sign out, call DELETE /api/merchant/me, which clears the cookie.
Endpoint
Request
Headers
No authentication is required — this endpoint is the authentication step.
Body Parameters
string
required
The email the account was registered with.
string
required
The account password. Verified against the bcrypt hash stored at signup.
Response
boolean
true on a successful login.object
Summary of the authenticated merchant.
merchant_token cookie (HttpOnly, SameSite=Lax, 7-day expiry). Browsers store and resend it automatically; subsequent calls to protected dashboard endpoints require it.
Logout
Signing out is handled byDELETE /api/merchant/me:
merchant_token cookie and returns:
Examples
Success Response
Error Responses
Notes
Login is only possible after the account is verified. Unverified accounts receive
HTTP 403 with "Please verify your email first." — complete the code at POST /api/merchant/verify first.
