Skip to main content
The login endpoint authenticates a verified merchant with email and password and issues a signed JWT stored in an HTTP-only merchant_token cookie. The cookie lasts 7 days and is required for the dashboard endpoints documented in this group — /me, /wallet, and /withdraw. To sign out, call DELETE /api/merchant/me, which clears the cookie.

Endpoint

Request

Headers

No authentication is required — this endpoint is the authentication step.

Body Parameters

string
required
The email the account was registered with.
string
required
The account password. Verified against the bcrypt hash stored at signup.

Response

boolean
true on a successful login.
object
Summary of the authenticated merchant.
The response also sets the merchant_token cookie (HttpOnly, SameSite=Lax, 7-day expiry). Browsers store and resend it automatically; subsequent calls to protected dashboard endpoints require it.

Logout

Signing out is handled by DELETE /api/merchant/me:
No body or headers are required. The response clears the merchant_token cookie and returns:

Examples

Success Response

Error Responses

Notes

Login is only possible after the account is verified. Unverified accounts receive HTTP 403 with "Please verify your email first." — complete the code at POST /api/merchant/verify first.
The merchant_token cookie is HttpOnly, so it is not readable from browser JavaScript. Use the response body’s merchant object if you need account details client-side.
Dashboard routes authenticate with the merchant_token cookie. For programmatic access, use your merchant API key via the x-api-key header instead — see GET /api/merchant/dashboard.