Revoke a refresh-token family
Revokes every active refresh token in the submitted token's family.
application/json- body
refreshToken*stringOpaque refresh token
0 <= length <= 512Family revoked or token already inactive
curl -X POST 'https://api.monetaryai.uz/api/v1/auth/logout' \ -H 'Content-Type: application/json' \ -d '{ "refreshToken": "string"}'Exchange credentials for a token pair POST
On the configured central host, email/password selects the oldest active membership. On tenant hosts, the tenant is taken from the host, not the body. A user of one tenant cannot authenticate against another tenant's subdomain. Repeated failures, from one address or against one account, are answered with 429 and Retry-After. When email 2FA is enabled, valid credentials without challengeId/code return 202 and queue an eight-digit code to the stored account email. Repeat this same login with password, challengeId and code to receive tokens. Codes expire in five minutes, permit five guesses and require provider acknowledgement. No tokens are issued at the challenge step. For Google Authenticator, 202 channel=TOTP requires repeating login with email, password and totpCode (six digits) or one unused recoveryCode. For TOTP, challengeId and expiresAt are null and no email is sent. On the second-factor submission, supply exactly one factor: paired email challengeId/code, totpCode, or recoveryCode; mixed factors return 400. A TOTP is accepted once across all memberships; wait for the next 30-second code after enrollment. Five Authenticator factor attempts per five minutes are permitted. The backend returns accessToken/refreshToken in the 200 JSON body, not browser cookies. The Next.js frontend BFF stores them in HttpOnly cookies and handles browser redirects; this backend endpoint does not redirect.
Request a company registration email link POST
Central host accepts valid email syntax with a routable mail domain for registration and returns 202. No account-existence/delivery disclosure; links point to configured /magic?token=... origin. Legacy tenant-host behavior uses the tenant host, not a body tenant identifier. After the same email-domain checks, compatibility mode returns 204, including unknown, inactive, throttled or disabled-delivery requests. This does not confirm account existence or delivery. No token is returned; delivery is opt-in and links use a trusted configured origin.