--- url: https://docs.youcan.shop/store-front/customers/login.md --- # Login a customer Endpoint: `https://my-store.youcan.shop/api/customers/login` Method: `POST` ## Parameters | Param Name | Param Type | Description | Required | | --- | --- | --- | --- | | `email` | string | Customer email | yes | | `password` | string | Customer password | yes | ## Response Send the token in the `Authorization` header of the customer endpoints: `Authorization: Bearer TOKEN`. The token expires after 30 days. A new password or a [logout](/store-front/customers/logout) revokes it. \[200] Ok ```json { "token": "1f3c9a…", "token_type": "bearer", "expires_in": 2592000 } ``` \[401] Unauthorized The email or the password is wrong. \[422] Unprocessable Entity ```json { "status": 422, "detail": "The given data was invalid.", "meta": { "fields": { "email": [ "The email field is required." ] } } } ``` ## Rate limits Login and [reset](/store-front/customers/reset) accept 10 requests a minute for each IP address and each email. [Create](/store-front/customers/create) and [recover](/store-front/customers/recover) accept 5. Above the limit the API returns `429`.