Admin auth

Email + password login for the back-office panel and token revocation. Paths are relative to the /api/v1 prefix; login is the one public admin endpoint, and the token it returns guards every other /admin/* route.

POST /admin/auth/login is public (rate-limited to 10 requests / minute). Every other admin endpoint requires Authorization: Bearer {token}. Admin only.

See Common errors.

Endpoints

Method URI Access Description
POST /admin/auth/login Public Exchange email + password for an admin token or a 2FA prompt
POST /admin/auth/2fa/verify Public Verify SMS OTP and get the admin token
POST /admin/auth/logout Admin Revoke the current admin token

POST /admin/auth/login

Authenticates an active admin. Inactive admins are treated as non-existent. If the admin has 2FA enabled, it sends an SMS OTP and returns a verify_token instead of the final Sanctum token.

Request body

Field Type Required Rules
email string yes valid email
password string yes non-empty

Response (2FA Disabled) 200

{
  "token": "12|abc...",
  "admin": {
    "id": 1,
    "name": "Ops Caracas",
    "email": "ops@aguita.app",
    "isSuperAdmin": false
  }
}

Response (2FA Enabled) 200

{
  "requires_2fa": true,
  "verify_token": "random32char...",
  "mocked": false
}

Errors

Status Body When
401 { "error": "InvalidCredentials" } Unknown email, wrong password, or the admin is inactive

POST /admin/auth/2fa/verify

Verifies the 6-digit SMS code sent during login. Must be called within 5 minutes of /login.

Request body

Field Type Required Rules
verify_token string yes The token received in the login step
code string yes The 6-digit SMS code

Response 200

{
  "token": "12|abc...",
  "admin": {
    "id": 1,
    "name": "Ops Caracas",
    "email": "ops@aguita.app",
    "isSuperAdmin": false
  }
}

Errors

Status Body When
401 { "error": "TokenExpiredOrInvalid" } The verify_token is wrong or expired
401 { "error": "AdminNotFound" } The admin was deleted or has no phone number
401 { "error": "InvalidOtp" } The code is incorrect

POST /admin/auth/logout

Revokes the bearer token used for the request.

Response 200

{ "ok": true }