Authentication
How to get a token with email and password, send it on every call, how long it lasts, the public routes, acting on behalf of another profile and how to set up a safe integration account.
The Memberfy API uses JWT tokens. You exchange an email and password for a token and send it on every call. The token belongs to a person (the account); what they can do depends on their role in the community of each call.
Get the token
curl -s -X POST https://api.memberfy.net/api/auth/login \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","password":"your-password"}'
Response (abridged):
{
"success": true,
"message": "Login successful.",
"data": {
"token": "eyJhbGciOi…",
"member": { "id": "…", "email": "[email protected]", "fullName": "Integration" }
}
}
Keep data.token.
Use the token
On every call that isn't public:
Authorization: Bearer <token>
Just the token, after Bearer . Almost always together with X-CommunityId.
curl -s https://api.memberfy.net/api/auth/me \
-H "Authorization: Bearer $TOKEN"
Lifetime
The token is valid for 7 days. There is no refresh token: when it's close to expiring, sign in again.
| Situation | Response |
|---|---|
| No token on a protected route | 401 · Authentication token is required |
| Invalid or expired token | 401 · Invalid or expired token |
| Token of someone who isn't a member of the community | 403 · Você não é membro desta comunidade. (you are not a member of this community) |
| Insufficient role | 403 · Função necessária: owner ou admin. Sua função: member (required role: owner or admin; your role: member) |
Public routes
These don't need a token: sign-in, sign-up, password recovery and reads of what is Public in the community (public spaces, the pricing page). On many reads the token is optional: without it, you get only what is public; with it, you also get what that person can see.
Acting on behalf of another profile
Owners, admins and moderators can send X-ProfileId: <profile id> to act as another profile in the same community (to post on behalf of someone on the team, for example). Rules:
- only those three roles: "Permissões insuficientes para usar X-ProfileId." (insufficient permissions to use X-ProfileId);
- the profile has to be in the same community: "Profile not found in this community.";
- nobody acts on behalf of an owner without being an owner;
- acting as another profile doesn't lend you their role: the permissions are still yours.
Integration account
For an integration (a CRM, an automation), create a member just for it:
- Invite
[email protected]with the minimum role the integration needs: Finance to read sales; Admin to create plans and products. - Keep the password in a secrets vault, never in the code.
- Sign in at the start of each run and reuse the token until it expires.
- If the token leaks, change the account's password; tokens already issued remain valid until they expire.
Endpoints
POST /api/auth/login | Email and password → token |
GET /api/auth/me | Who owns the token |
POST /api/auth/register | Sign-up (fullName, email, password with at least 8 characters, an uppercase letter, a lowercase letter and a number) |
PUT /api/auth/change-password | Change the password |
POST /api/auth/recovery-password | Recover the password |
POST /api/auth/set-password | Set the password from the invite link (id, token, password). Answers 400 for a wrong token and 410 for a used or expired link |
Good practices
- Never put the token in the code of a public website: anyone could read it.
- Always use HTTPS (
https://api.memberfy.net). - Handle a
401by signing in again once; if it fails again, stop and raise an alert.