Medusa Auth API

The Auth API from Medusa — 2 operation(s) for auth.

OpenAPI Specification

medusa-js-auth-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Medusa Store Auth API
  version: '2'
  description: 'Medusa Store API - the public REST surface consumed by storefronts and

    end-customer clients of a Medusa commerce application. Provides carts,

    products, collections, categories, regions, customers, orders, payments,

    shipping, returns, and gift cards. Requests are scoped by sales channel

    using a publishable API key passed in the x-publishable-api-key header.

    Customer-scoped requests use a JWT bearer token or a cookie session.

    '
  contact:
    name: Medusa Docs - Store API
    url: https://docs.medusajs.com/api/store
servers:
- url: '{medusaApplicationUrl}'
  description: Your Medusa application
  variables:
    medusaApplicationUrl:
      default: http://localhost:9000
      description: Base URL of your Medusa server (no trailing slash)
security:
- publishableApiKey: []
  bearerAuth: []
- publishableApiKey: []
  cookieAuth: []
tags:
- name: Auth
paths:
  /auth/customer/{auth_provider}:
    post:
      tags:
      - Auth
      summary: Authenticate as a customer
      security:
      - publishableApiKey: []
      parameters:
      - in: path
        name: auth_provider
        required: true
        schema:
          type: string
          example: emailpass
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                email:
                  type: string
                password:
                  type: string
      responses:
        '200':
          description: JWT token issued
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
  /auth/session:
    post:
      tags:
      - Auth
      summary: Exchange a JWT for a cookie session
      responses:
        '200':
          description: Session established
components:
  securitySchemes:
    publishableApiKey:
      type: apiKey
      in: header
      name: x-publishable-api-key
      description: Publishable API key that scopes requests to one or more sales channels.
    bearerAuth:
      type: http
      scheme: bearer
      description: JWT bearer token obtained via /auth/customer/{auth_provider}.
    cookieAuth:
      type: apiKey
      in: cookie
      name: connect.sid