Queek docs
Storefront endpoint reference

Email

POST
/auth/email/request-otp

Sends a one-time code to the shopper’s email for sign-in or registration.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/email/request-otp" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "email": "[email protected]"  }'
{  "status": "success",  "message": "OTP sent",  "data": {    "email": "[email protected]",    "next_action": "verify_otp",    "user_exists": true,    "expires_in": 300,    "resend_in": 60  }}
POST
/auth/email/verify-otp

Verifies the email code and signs the customer in, returning the session tokens.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/email/verify-otp" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "email": "[email protected]",    "otp_code": "730451"  }'
{  "status": "success",  "message": "Email verified",  "data": {    "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9",    "token_type": "Bearer",    "expires_in": 3600,    "expires_at": "2026-09-25T16:58:00+01:00",    "refresh_expires_in": 2592000,    "refresh_expires_at": "2026-10-25T15:58:00+01:00",    "platform": "client_web",    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    }  }}
POST
/auth/email/register-otp

Registers a new customer with a verified email code.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/email/register-otp" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "first_name": "Adaeze",    "last_name": "Okafor",    "verified_token": "evt_7f3a9c2e1b5d48a6c0e2f4a6b8d0c1e3"  }'
{  "status": "success",  "message": "Account created",  "data": {    "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9",    "token_type": "Bearer",    "expires_in": 3600,    "expires_at": "2026-09-25T16:58:00+01:00",    "refresh_expires_in": 2592000,    "refresh_expires_at": "2026-10-25T15:58:00+01:00",    "platform": "client_web",    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    },    "is_new_user": true  }}
POST
/auth/email/login

Signs a customer in with email and password, returning the session tokens.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/email/login" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "email": "[email protected]",    "password": "s4nd4l-f0r-As0-ebe"  }'
{  "status": "success",  "message": "Signed in",  "data": {    "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9",    "token_type": "Bearer",    "expires_in": 3600,    "expires_at": "2026-09-25T16:58:00+01:00",    "refresh_expires_in": 2592000,    "refresh_expires_at": "2026-10-25T15:58:00+01:00",    "platform": "client_web",    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    }  }}
POST
/auth/email/register-password

Registers a new customer with email and password.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/email/register-password" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "first_name": "Adaeze",    "last_name": "Okafor",    "email": "[email protected]",    "password": "s4nd4l-f0r-As0-ebe"  }'
{  "status": "success",  "message": "Account created",  "data": {    "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9",    "token_type": "Bearer",    "expires_in": 3600,    "expires_at": "2026-09-25T16:58:00+01:00",    "refresh_expires_in": 2592000,    "refresh_expires_at": "2026-10-25T15:58:00+01:00",    "platform": "client_web",    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    },    "is_new_user": true  }}
POST
/auth/email/forgot-password

Accepted. The answer is identical whether the address holds an account or not, so it can never be used to probe who shops here — check the inbox, not this response.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

The body of the forgot-password call: the account email that receives the reset code. Declared here (rather than inline on the route) so the public reference shows the body.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/email/forgot-password" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "email": "[email protected]"  }'
{  "status": "success",  "message": "If your account exists, you will receive a password reset email."}
POST
/auth/email/reset-password

Consumes the emailed link credential and sets the new password.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/email/reset-password" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "token": "rst_4b8e2f1a9c3d47e5a6b0c8d2e4f6a1b3",    "email": "[email protected]",    "password": "n3w-s4nd4l-f0r-As0",    "password_confirmation": "n3w-s4nd4l-f0r-As0"  }'
{  "status": "success",  "message": "Your password has been reset successfully."}