Skip to content

Authentication

How to get a token with email and password, send it on every call, how long it lasts, the public routes, acting on behalf of another profile and how to set up a safe integration account.

The Memberfy API uses JWT tokens. You exchange an email and password for a token and send it on every call. The token belongs to a person (the account); what they can do depends on their role in the community of each call.

Get the token

curl -s -X POST https://api.memberfy.net/api/auth/login \
  -H "Content-Type: application/json" \
  -d '{"email":"integration@memberfy.net","password":"your-password"}'

Response (abridged):

{
  "success": true,
  "message": "Login successful.",
  "data": {
    "token": "eyJhbGciOi…",
    "member": { "id": "…", "email": "integration@memberfy.net", "fullName": "Integration" }
  }
}

Keep data.token.

Use the token

On every call that isn't public:

Authorization: Bearer <token>

Just the token, after Bearer . Almost always together with X-CommunityId.

curl -s https://api.memberfy.net/api/auth/me \
  -H "Authorization: Bearer $TOKEN"

Lifetime

The token is valid for 7 days. There is no refresh token: when it's close to expiring, sign in again.

SituationResponse
No token on a protected route401 · Authentication token is required
Invalid or expired token401 · Invalid or expired token
Token of someone who isn't a member of the community403 · Você não é membro desta comunidade. (you are not a member of this community)
Insufficient role403 · Função necessária: owner ou admin. Sua função: member (required role: owner or admin; your role: member)

Public routes

These don't need a token: sign-in, sign-up, password recovery and reads of what is Public in the community (public spaces, the pricing page). On many reads the token is optional: without it, you get only what is public; with it, you also get what that person can see.

Acting on behalf of another profile

Owners, admins and moderators can send X-ProfileId: <profile id> to act as another profile in the same community (to post on behalf of someone on the team, for example). Rules:

  • only those three roles: "Permissões insuficientes para usar X-ProfileId." (insufficient permissions to use X-ProfileId);
  • the profile has to be in the same community: "Profile not found in this community.";
  • nobody acts on behalf of an owner without being an owner;
  • acting as another profile doesn't lend you their role: the permissions are still yours.

Integration account

For an integration (a CRM, an automation), create a member just for it:

  1. Invite integration@memberfy.net with the minimum role the integration needs: Finance to read sales; Admin to create plans and products.
  2. Keep the password in a secrets vault, never in the code.
  3. Sign in at the start of each run and reuse the token until it expires.
  4. If the token leaks, change the account's password; tokens already issued remain valid until they expire.

Endpoints

POST /api/auth/loginEmail and password → token
GET /api/auth/meWho owns the token
POST /api/auth/registerSign-up (fullName, email, password with at least 8 characters, an uppercase letter, a lowercase letter and a number)
PUT /api/auth/change-passwordChange the password
POST /api/auth/recovery-passwordRecover the password
POST /api/auth/set-passwordSet the password from the invite link (id, token, password). Answers 400 for a wrong token and 410 for a used or expired link

Good practices

  • Never put the token in the code of a public website: anyone could read it.
  • Always use HTTPS (https://api.memberfy.net).
  • Handle a 401 by signing in again once; if it fails again, stop and raise an alert.