POST /api/v1/auth/setup # Public
Create the first admin account.
First run only — refused once any user exists. Returns a session cookie
and an API token, the latter shown exactly once.
Request body required
application/json
object
display_name string | null
Responses
200 Created. Sets td_session.
application/json
object
The first admin, signed in, with a token.
user_id integer · int64 required
token string required
An API token with submit and read. Shown once, never again.
400 Malformed or rejected input.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
POST /api/v1/auth/login # Public
Sign in.
Sets the td_session cookie. Rate limited on repeated failure.
This is the mobile flow. Post credentials once, then mint a named
token and store that — the cookie expires hard at 7 days with no sliding
renewal, and cannot be revoked per device.
Request body required
application/json
Responses
200 Signed in. Sets td_session.
application/json
object
user_id integer · int64 required
is_admin boolean required
401 Bad credentials, or the account is disabled.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
429 Too many failed attempts from this address. Retry-After says how long to wait.
application/json
object
Every error body in the API has this shape.
code integer · int32 required
error string required
Human-readable. Not a stable identifier — do not branch on it.
POST /api/v1/auth/logout # Session
Sign out.
Clears the session. The clear cookie carries identical attributes to the
one that was set — mismatched attributes make logout silently fail. Never
fails: with no session it only clears the cookie.
Responses
200 Signed out. status is logged out.
application/json
object
An acknowledgement with nothing else to report.
status names what happened — ok, updated, deleted, cleared,
started and so on; the operation says which it sends. A client needs only
the HTTP status to know it worked.