Sends a one-time code to the shopper’s email for sign-in or registration.
Authorization
clientKey The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
In: header
Header Parameters
Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/email/request-otp" \ -H "X-Client-Key: {{clientKey}}" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]" }'{ "status": "success", "message": "OTP sent", "data": { "email": "[email protected]", "next_action": "verify_otp", "user_exists": true, "expires_in": 300, "resend_in": 60 }}Verifies the email code and signs the customer in, returning the session tokens.
Authorization
clientKey The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
In: header
Header Parameters
Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/email/verify-otp" \ -H "X-Client-Key: {{clientKey}}" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]", "otp_code": "730451" }'{ "status": "success", "message": "Email verified", "data": { "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3", "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3", "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9", "token_type": "Bearer", "expires_in": 3600, "expires_at": "2026-09-25T16:58:00+01:00", "refresh_expires_in": 2592000, "refresh_expires_at": "2026-10-25T15:58:00+01:00", "platform": "client_web", "user": { "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51", "name": "Adaeze Okafor", "email": "[email protected]", "phone": "+2348031234567", "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg", "country": "Nigeria", "state": "Lagos", "region": null, "city": "Lekki", "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos", "map_lat": "6.4474000", "map_lng": "3.4712000", "is_rider": false, "rider_approved": false, "profile_complete": true } }}Registers a new customer with a verified email code.
Authorization
clientKey The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
In: header
Header Parameters
Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/email/register-otp" \ -H "X-Client-Key: {{clientKey}}" \ -H "Content-Type: application/json" \ -d '{ "first_name": "Adaeze", "last_name": "Okafor", "verified_token": "evt_7f3a9c2e1b5d48a6c0e2f4a6b8d0c1e3" }'{ "status": "success", "message": "Account created", "data": { "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3", "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3", "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9", "token_type": "Bearer", "expires_in": 3600, "expires_at": "2026-09-25T16:58:00+01:00", "refresh_expires_in": 2592000, "refresh_expires_at": "2026-10-25T15:58:00+01:00", "platform": "client_web", "user": { "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51", "name": "Adaeze Okafor", "email": "[email protected]", "phone": "+2348031234567", "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg", "country": "Nigeria", "state": "Lagos", "region": null, "city": "Lekki", "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos", "map_lat": "6.4474000", "map_lng": "3.4712000", "is_rider": false, "rider_approved": false, "profile_complete": true }, "is_new_user": true }}Signs a customer in with email and password, returning the session tokens.
Authorization
clientKey The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
In: header
Header Parameters
Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/email/login" \ -H "X-Client-Key: {{clientKey}}" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]", "password": "s4nd4l-f0r-As0-ebe" }'{ "status": "success", "message": "Signed in", "data": { "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3", "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3", "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9", "token_type": "Bearer", "expires_in": 3600, "expires_at": "2026-09-25T16:58:00+01:00", "refresh_expires_in": 2592000, "refresh_expires_at": "2026-10-25T15:58:00+01:00", "platform": "client_web", "user": { "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51", "name": "Adaeze Okafor", "email": "[email protected]", "phone": "+2348031234567", "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg", "country": "Nigeria", "state": "Lagos", "region": null, "city": "Lekki", "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos", "map_lat": "6.4474000", "map_lng": "3.4712000", "is_rider": false, "rider_approved": false, "profile_complete": true } }}Registers a new customer with email and password.
Authorization
clientKey The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
In: header
Header Parameters
Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/email/register-password" \ -H "X-Client-Key: {{clientKey}}" \ -H "Content-Type: application/json" \ -d '{ "first_name": "Adaeze", "last_name": "Okafor", "email": "[email protected]", "password": "s4nd4l-f0r-As0-ebe" }'{ "status": "success", "message": "Account created", "data": { "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3", "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3", "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9", "token_type": "Bearer", "expires_in": 3600, "expires_at": "2026-09-25T16:58:00+01:00", "refresh_expires_in": 2592000, "refresh_expires_at": "2026-10-25T15:58:00+01:00", "platform": "client_web", "user": { "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51", "name": "Adaeze Okafor", "email": "[email protected]", "phone": "+2348031234567", "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg", "country": "Nigeria", "state": "Lagos", "region": null, "city": "Lekki", "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos", "map_lat": "6.4474000", "map_lng": "3.4712000", "is_rider": false, "rider_approved": false, "profile_complete": true }, "is_new_user": true }}Accepted. The answer is identical whether the address holds an account or not, so it can never be used to probe who shops here — check the inbox, not this response.
Authorization
clientKey The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
In: header
Header Parameters
Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
The body of the forgot-password call: the account email that receives the reset code. Declared here (rather than inline on the route) so the public reference shows the body.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/email/forgot-password" \ -H "X-Client-Key: {{clientKey}}" \ -H "Content-Type: application/json" \ -d '{ "email": "[email protected]" }'{ "status": "success", "message": "If your account exists, you will receive a password reset email."}Consumes the emailed link credential and sets the new password.
Authorization
clientKey The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
In: header
Header Parameters
Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.
Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/email/reset-password" \ -H "X-Client-Key: {{clientKey}}" \ -H "Content-Type: application/json" \ -d '{ "token": "rst_4b8e2f1a9c3d47e5a6b0c8d2e4f6a1b3", "email": "[email protected]", "password": "n3w-s4nd4l-f0r-As0", "password_confirmation": "n3w-s4nd4l-f0r-As0" }'{ "status": "success", "message": "Your password has been reset successfully."}