POST /api/login# Authenticate a client account with email and password, and return a JWT token for regular client API access. Request Body# Parameter Type Required Description emailstring Yes Client account email address. passwordstring Yes Client account password. tokenstring No Optional Shopify store token used to bind a store to the client after successful login.
Success Response# Response 200 OK (regular client)# {
"token" : "jwt_token_string" ,
"expire_time" : "2026-05-16T08:30:00.000Z"
} Field Type Description token string JWT token for authenticated client API access. expire_time string Token expiration time in ISO 8601 format.
Response 200 OK (sub-client / client with master_id)# {
"token" : "jwt_token_string" ,
"expire_time" : "2026-05-16T08:30:00.000Z" ,
"fore_permission" : true ,
"redirect_domain" : "https://example.com"
} Field Type Description token string JWT token for authenticated client API access. expire_time string Token expiration time in ISO 8601 format. fore_permission boolean Frontend permission flag returned for sub-client accounts. redirect_domain string Redirect domain configured for the client account. Returned for sub-client accounts.
Error Response# Response 401 Unauthorized (invalid credentials)# {
"error" : "Invalid email or password" ,
"status" : 401
} Response 401 Unauthorized (login blocked)# {
"error" : "LOGIN_ACCESS_DENIED_ERROR" ,
"status" : 401
} Note: The actual error message for blocked login is returned from backend constant Client::LOGIN_ACCESS_DENIED_ERROR. Response 200 OK (invalid domain in production environment)# {
"error" : "Invalid domain" ,
"redirect_domain" : "https://example.com"
} This response is returned when the current request domain does not match the client account's configured redirect domain in the production environment. Notes# The token returned by /api/login is the standard client token for regular authenticated client APIs.
email is normalized to lowercase before authentication.
If token is provided and valid, the related Shopify store will be bound to the client after successful login.
Request Provide your bearer token in the Authorization
header when making requests to protected resources. Example: Authorization: Bearer ********************
Body Params multipart/form-data Required
Request Code Samples
curl --location 'http://stage-client.dropshippinglite.com/api/login' \
--header 'Authorization: Bearer <token>' \
--form 'email="example@dropshippinglite.com"' \
--form 'password="sample_password"' \
--form 'token=""' Responses application/json
Generate Code
{
"token" : "string" ,
"expire_time" : "string"
} Modified at 2026-05-09 08:35:32