Authentication and token usage
Register or log in, capture the JWT, and authenticate protected Conduit requests with the Token header.
Use this guide when a request needs the signed JSON Web Token (JWT) issued by Conduit. You will register or log in, extract the token from the user response, and send it as Authorization: Token <jwt> on protected requests.
Before you begin
Choose a base URL, such as https://api.realworld.show/api, and have curl and jq available for the shell examples. Registration requires a unique username and email plus a password. Login requires the email and password for an existing account.
Authentication flow
The token is returned by either public authentication operation and becomes a request header for protected operations.
Log in
POST /users/login authenticates an existing user and returns the user envelope with a non-empty token.
Authenticates an existing user with email and password.
/users/loginThe request body is JSON.
Object containing the required `email` and `password` strings.
curl --request POST \
--url https://api.realworld.show/api/users/login \
--header 'Content-Type: application/json' \
--header 'Content-Type: application/json' \
--data '{
"user": "email, password"
}'{ "user": { "email": "reader@example.com", "token": "demo-jwt-token", "username": "reader", "bio": null, "image": null } }Register a user
POST /users creates a new account and returns the new user's token.
Creates a Conduit user account.
/usersThe request body is JSON.
Object containing the required `username`, `email`, and `password` strings.
curl --request POST \
--url https://api.realworld.show/api/users \
--header 'Content-Type: application/json' \
--header 'Content-Type: application/json' \
--data '{
"user": "username, email, password"
}'{ "user": { "email": "reader@example.com", "token": "demo-jwt-token", "username": "reader", "bio": null, "image": null } }Register and use a token
Define a unique test identity and the API base URL.
BASE_URL="https://api.realworld.show/api"
RUN_ID="$(date +%s)"
USERNAME="auth_${RUN_ID}"
EMAIL="auth_${RUN_ID}@example.com"
PASSWORD="password123"The values are ready for POST /users. The request body must wrap the required fields in a user object.
Register a new account with POST /users.
REGISTERED="$(curl --fail-with-body --silent --show-error \
--request POST "$BASE_URL/users" \
--header 'Content-Type: application/json' \
--data "{\"user\":{\"username\":\"$USERNAME\",\"email\":\"$EMAIL\",\"password\":\"$PASSWORD\"}}")"The successful response has status 201 and contains user.token. If the account already exists, use login instead:
REGISTERED="$(curl --fail-with-body --silent --show-error \
--request POST "$BASE_URL/users/login" \
--header 'Content-Type: application/json' \
--data "{\"user\":{\"email\":\"$EMAIL\",\"password\":\"$PASSWORD\"}}")"Successful login has status 200 and returns the same user representation with a non-empty token.
Extract the token from the response and fail if the response does not contain a usable string.
TOKEN="$(jq -er '.user.token' <<<"$REGISTERED")"TOKEN now contains the JWT issued by registration or login. The response also includes username, email, and nullable bio and image fields.
Call the protected current-user endpoint with the exact scheme name Token.
curl --fail-with-body --silent --show-error \
--request GET "$BASE_URL/user" \
--header "Authorization: Token $TOKEN"The server returns 200 and the authenticated user object. In JavaScript, the equivalent header is Authorization: \Token ${token}\` in a fetch` request.
Make one request without the header to confirm that the protected boundary is working.
curl --silent --show-error \
--request GET "$BASE_URL/user"The response has status 401 and the error envelope contains errors.token[0] with the value is missing. Invalid login credentials return 401 with errors.credentials[0] set to invalid; blank required credentials return 422.
Next steps
Use the authenticated request pattern for reading and updating the current user, profiles and follows, article creation, and the followed-user feed. For the common response and error shapes, see Response envelopes and resource models and Error envelope and HTTP status behavior.