# Login a customer

Logs in a customer.

Endpoint: POST /authentication-tokens
Version: latest
Security: SecretApiKey, JWT, PublishableApiKey

## Security:

  - `SecretApiKey` (unknown)
    apiKey in header REB-APIKEY

  - `JWT` (unknown)
    http bearer JWT

  - `PublishableApiKey` (unknown)
    apiKey in header Authorization

## Request body:

  - `application/json` (unknown)
    AuthenticationToken resource.

## Request fields (application/json):

  - `username` (string, required)
    Username associated with the authentication token.

  - `password` (string, required)
    Password associated with the authentication token.

  - `mode` (string)
    Specifies the authentication verification method.
The `password` token requires the user to enter a password to log in.
The `passwordless` token, requires a secret API key to log in.
To obtain an API key, see [Manage API keys](https://www.rebilly.com/docs/dev-docs/api-keys/#manage-api-keys).
    Enum: "password"

  - `customerId` (string)
    ID of the customer resource.
    Example: cus_0YV7DDSDD1C8DA64KHH2W33CPF

  - `otpRequired` (boolean)
    Specifies if a One-Time Password (OTP) is required to exchange the authentication token.

  - `credentialId` (string)
    Unique resource ID.
    Example: 4f6cf35x-2c4y-483z-a0a9-158621f77a21

  - `expiredTime` (string)
    Date and time when the token expired.

## Response 201:

  - `201` (unknown)
    Login successful.

## Response 201 fields (application/json):

  - `username` (string, required)
    Username of the customer who is associated with the authentication token.

  - `customerId` (string)
    ID of the customer resource.
    Example: cus_0YV7DDSDD1C8DA64KHH2W33CPF

  - `token` (string)
    ID of the authentication token.

  - `otpRequired` (boolean)
    Specifies if a One-Time Password (OTP) is required to exchange the authentication token.

  - `credentialId` (string)
    Unique resource ID.
    Example: 4f6cf35x-2c4y-483z-a0a9-158621f77a21

  - `expiredTime` (string | null)
    Date and time when the token expired.

  - `_links` (array)
    Related links.

  - `_links.href` (string)
    Link URL.

  - `_links.rel` (string)
    Type of link.
    Enum: "self"

## Response 201 headers (application/json):

  - `Location` (string)
    Location of the related resource.
    Example: https://api.rebilly.com/example

  - `X-RateLimit-Limit` (integer)
    Total number of rate limit tokens for this request within a rate limit period.
For more information, see [Rate limits](#section/Rate-limits).
    Example: 3600

  - `X-RateLimit-Remaining` (integer)
    Remaining number of rate limit tokens for this request within the rate limit period. 
For example, in the sandbox environment, rate limits for non-GET endpoints are set at 3000 requests per 10 minutes.
    Example: 3600

## Response 401:

  - `401` (unknown)
    Unauthorized access.
Invalid credentials used.

## Response 401 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 403:

  - `403` (unknown)
    Access forbidden.

## Response 403 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 422:

  - `422` (unknown)
    Invalid data sent.

## Response 422 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

  - `invalidFields` (array)
    Invalid field details.
    Example: [{"field":"field1","message":"field1 is invalid"},{"field":"subObject.field2","message":"field2 is invalid"},{"field":"subObject.field2","message":"another error in the field2"}]

  - `invalidFields.field` (string)
    Name of the field.
Dot notation is used for nested object field names.

  - `invalidFields.message` (string)
    Message field.

## Response 429:

  - `429` (unknown)
    Request rate limit exceeded.

## Response 429 fields (application/json):

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".
    Example: about:blank

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.
    Example: Rate Limit Exceeded

  - `status` (integer)
    HTTP status code.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.
    Example: A request cannot be executed because the user has sent too many requests within a certain period of time

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 429 headers (application/json):

  - `X-RateLimit-Retry-After` (integer)
    UTC timestamp after which the rate limit resets and the request can be retried.
    Example: 1713187500

