Email + password login for the back-office panel and token revocation. Paths are
relative to the /api/v1 prefix; login is the one public admin endpoint, and the
token it returns guards every other /admin/* route.
POST /admin/auth/loginis public (rate-limited to 10 requests / minute). Every other admin endpoint requiresAuthorization: Bearer {token}. Admin only.
See Common errors.
| Method | URI | Access | Description |
|---|---|---|---|
POST |
/admin/auth/login |
Public | Exchange email + password for an admin token or a 2FA prompt |
POST |
/admin/auth/2fa/verify |
Public | Verify SMS OTP and get the admin token |
POST |
/admin/auth/logout |
Admin | Revoke the current admin token |
Authenticates an active admin. Inactive admins are treated as non-existent.
If the admin has 2FA enabled, it sends an SMS OTP and returns a verify_token instead of the final Sanctum token.
Request body
| Field | Type | Required | Rules |
|---|---|---|---|
email |
string | yes | valid email |
password |
string | yes | non-empty |
Response (2FA Disabled) 200
{
"token": "12|abc...",
"admin": {
"id": 1,
"name": "Ops Caracas",
"email": "ops@aguita.app",
"isSuperAdmin": false
}
}
Response (2FA Enabled) 200
{
"requires_2fa": true,
"verify_token": "random32char...",
"mocked": false
}
Errors
| Status | Body | When |
|---|---|---|
401 |
{ "error": "InvalidCredentials" } |
Unknown email, wrong password, or the admin is inactive |
Verifies the 6-digit SMS code sent during login. Must be called within 5 minutes of /login.
Request body
| Field | Type | Required | Rules |
|---|---|---|---|
verify_token |
string | yes | The token received in the login step |
code |
string | yes | The 6-digit SMS code |
Response 200
{
"token": "12|abc...",
"admin": {
"id": 1,
"name": "Ops Caracas",
"email": "ops@aguita.app",
"isSuperAdmin": false
}
}
Errors
| Status | Body | When |
|---|---|---|
401 |
{ "error": "TokenExpiredOrInvalid" } |
The verify_token is wrong or expired |
401 |
{ "error": "AdminNotFound" } |
The admin was deleted or has no phone number |
401 |
{ "error": "InvalidOtp" } |
The code is incorrect |
Revokes the bearer token used for the request.
Response 200
{ "ok": true }