curl --request POST \
--url 'https://gateway.amana.io/auth/login' \
--header 'Content-Type: application/json' \
--data '{
"email": "jsmith@example.com",
"password": "<string>"
}'
import requests
url = "https://gateway.amana.io/auth/login"
headers = {"Content-Type": "application/json"}
payload = {
"email": "jsmith@example.com",
"password": "<string>"
}
response = requests.request("POST", url, json=payload, headers=headers)
print(response.json())
const response = await fetch('https://gateway.amana.io/auth/login', {
method: 'POST',
headers: {"Content-Type": "application/json"},
body: JSON.stringify({"email": "jsmith@example.com", "password": "<string>"}),
});
console.log(await response.json());
{
"access_token": "<string>",
"refresh_token": "<string>",
"passkey": true
}
{
"error": "<string>",
"message": "<string>"
}
{
"error": "<string>",
"email": "<string>",
"ok": true
}
{
"error": "<string>",
"ok": true
}
{
"error": "<string>",
"message": "<string>",
"details": {}
}
{
"error": "<string>",
"ok": true
}
{
"error": "<string>",
"message": "<string>",
"details": {}
}
Authentication
Log in
Sign in with email and password to get an access token and a refresh token. Call this first, then send the access token as a Bearer token on every authenticated request.
POST
/
auth
/
login
curl --request POST \
--url 'https://gateway.amana.io/auth/login' \
--header 'Content-Type: application/json' \
--data '{
"email": "jsmith@example.com",
"password": "<string>"
}'
import requests
url = "https://gateway.amana.io/auth/login"
headers = {"Content-Type": "application/json"}
payload = {
"email": "jsmith@example.com",
"password": "<string>"
}
response = requests.request("POST", url, json=payload, headers=headers)
print(response.json())
const response = await fetch('https://gateway.amana.io/auth/login', {
method: 'POST',
headers: {"Content-Type": "application/json"},
body: JSON.stringify({"email": "jsmith@example.com", "password": "<string>"}),
});
console.log(await response.json());
{
"access_token": "<string>",
"refresh_token": "<string>",
"passkey": true
}
{
"error": "<string>",
"message": "<string>"
}
{
"error": "<string>",
"email": "<string>",
"ok": true
}
{
"error": "<string>",
"ok": true
}
{
"error": "<string>",
"message": "<string>",
"details": {}
}
{
"error": "<string>",
"ok": true
}
{
"error": "<string>",
"message": "<string>",
"details": {}
}
Headers
string
Body
Content type:application/json
string<email>
required
User’s email address.
string
required
User’s password.Minimum length:
8Response
200 Success.
string
JWT access token to be used as Bearer token in Authorization header
string
Also set as an httpOnly cookie for web clients; mobile clients store and POST this back to /auth/refresh
boolean
Whether the account has at least one registered passkey
Possible Errors
| Error | Possible cause | What to do |
|---|---|---|
| 400 | Invalid or missing field | Check the request against the schema. |
| 401 | Email or password is incorrect | Check the credentials and try again. |
| 403 | IP not whitelisted, or account restricted | Confirm your IP is whitelisted; otherwise contact Amana. |
| 404 | The requested item doesn’t exist | Check the ID or path parameter. |
| 429 / 5xx | Rate limit, or temporary issue on our side | Retry with backoff; contact support if it persists. |
curl --request POST \
--url 'https://gateway.amana.io/auth/login' \
--header 'Content-Type: application/json' \
--data '{
"email": "jsmith@example.com",
"password": "<string>"
}'
import requests
url = "https://gateway.amana.io/auth/login"
headers = {"Content-Type": "application/json"}
payload = {
"email": "jsmith@example.com",
"password": "<string>"
}
response = requests.request("POST", url, json=payload, headers=headers)
print(response.json())
const response = await fetch('https://gateway.amana.io/auth/login', {
method: 'POST',
headers: {"Content-Type": "application/json"},
body: JSON.stringify({"email": "jsmith@example.com", "password": "<string>"}),
});
console.log(await response.json());
{
"access_token": "<string>",
"refresh_token": "<string>",
"passkey": true
}
{
"error": "<string>",
"message": "<string>"
}
{
"error": "<string>",
"email": "<string>",
"ok": true
}
{
"error": "<string>",
"ok": true
}
{
"error": "<string>",
"message": "<string>",
"details": {}
}
{
"error": "<string>",
"ok": true
}
{
"error": "<string>",
"message": "<string>",
"details": {}
}
Last modified on October 8, 2026
