REST API - Auth#

Project auth (end-users)#

All endpoints require the project API key (or a project-user session).

EndpointMethodDescription
/projects/{id}/auth/signupPOSTCreate a user (email, password, full_name, phone)
/projects/{id}/auth/signinPOSTSign in with email/password
/projects/{id}/auth/otp/requestPOSTSend an SMS OTP
/projects/{id}/auth/otp/verifyPOSTVerify the OTP, get a session
/projects/{id}/auth/reset-passwordPOSTEmail a reset code
/projects/{id}/auth/reset-password/confirmPOSTVerify code + set new password

Signup

POST /projects/{project_id}/auth/signup
X-AFRIBASE-API-Key: raf_live_...
Text
{
  "email": "user@example.com",
  "password": "strong-pass1",
  "full_name": "Asha Mwinyi",
  "phone": "+255712345678"
}
JSON

All fields are required; passwords need 8+ chars with at least one letter and one number; phones need a country code (+255 / +254).

Signin

POST /projects/{project_id}/auth/signin
Text
{ "email": "user@example.com", "password": "strong-pass1" }
JSON

Response contains user + tokens (access_token valid per-project, used by RLS as the authenticated subject).

OTP

POST /projects/{project_id}/auth/otp/request   { "phone": "+255712345678" }
POST /projects/{project_id}/auth/otp/verify    { "phone": "...", "code": "123456", "full_name": "Asha Mwinyi" }
Text

Password reset

POST /projects/{project_id}/auth/reset-password            { "email": "..." }
POST /projects/{project_id}/auth/reset-password/confirm    { "email": "...", "code": "123456", "new_password": "..." }
Text

The code is 6 digits, valid 15 minutes, single-use.

Users management#

EndpointMethod
/projects/{id}/auth/usersGET (list)
/projects/{id}/auth/users/{userID}GET / PATCH / DELETE
/projects/{id}/auth/settingsGET / PUT