Skip to content
TUMR DOCS
Docsapi referenceAuthentication & Tokens
API Reference

Authentication & Tokens

Endpoints for obtaining JWTs, registering users, and managing API keys.

POST

Exchange email and password credentials for an access and refresh JWT pair.

Authentication: Public / None

Request Body Fields

FieldTypeRequirementDescription
emailstringRequired

Registered account email address.

passwordstringRequired

Account password string.

Request ExampleHTTPS Live Endpoint
curl -X POST https://api.tumr.app/api/v1/auth/login/ \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]", "password": "StrongPassword123!" }'
Response Payload
200 OK
application/json
{ "access": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX2lkIjoiZj...", "refresh": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyX2lkIjoiZj..." }
POST

Generate a new Secret API Key for programmatic backend integration.

Authentication: JWT (Admin or Merchant)

Request Body Fields

FieldTypeRequirementDescription
namestringOptional

Friendly name identifier for the key (e.g. "Shopify Backend").

Default: Default
modestringOptional

Key mode.

Allowed:"live""test"
Default: test
Request ExampleHTTPS Live Endpoint
curl -X POST https://api.tumr.app/api/v1/auth/api-keys/ \ -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "name": "Production Shopify Plugin", "mode": "live" }'
Response Payload
201 Created
application/json
{ "id": "99481a8b-4821-4910-b910-481902849102", "name": "Production Shopify Plugin", "mode": "live", "key": "tumr_live_...", "created_at": "2026-08-14T10:00:00Z" }