Quickstart: make your first Conduit request
Register a user with the hosted Conduit API, capture the returned token, and call a protected endpoint.
In this tutorial, you will create a disposable Conduit account on the hosted demo API, capture its JWT, and use that token to request the current user. The API base URL is https://api.realworld.show/api; no API key is required.
Before you begin
You need curl and jq in a shell. Use a unique username and email for each run because the API rejects a duplicate username or email with 409. The example uses the reserved-looking example.com domain and a generated suffix; replace it with another test address if your environment filters that domain.
Create shell variables for the API base URL and a unique suffix. The suffix makes the registration safe to repeat.
BASE_URL="https://api.realworld.show/api"
RUN_ID="$(date +%s)"
USERNAME="conduit_${RUN_ID}"
EMAIL="conduit_${RUN_ID}@example.com"
PASSWORD="password123"The variables are available for the remaining commands, and the password meets the documented example behavior used by the API suite.
Send the required user.username, user.email, and user.password fields to POST /users.
curl --fail-with-body --silent --show-error \
--request POST "$BASE_URL/users" \
--header 'Content-Type: application/json' \
--data "{\"user\":{\"username\":\"$USERNAME\",\"email\":\"$EMAIL\",\"password\":\"$PASSWORD\"}}"The server returns 201 and a JSON object under user. The object includes your username, email, nullable bio and image fields, and a non-empty token string.
Run the registration request again while piping the response to jq, then store the token in a shell variable. This command uses a fresh identity so it does not collide with the previous example.
RUN_ID="$(date +%s)"
USERNAME="conduit_${RUN_ID}"
EMAIL="conduit_${RUN_ID}@example.com"
RESPONSE="$(curl --fail-with-body --silent --show-error \
--request POST "$BASE_URL/users" \
--header 'Content-Type: application/json' \
--data "{\"user\":{\"username\":\"$USERNAME\",\"email\":\"$EMAIL\",\"password\":\"$PASSWORD\"}}")"
TOKEN="$(jq -er '.user.token' <<<"$RESPONSE")"jq -e exits with an error if .user.token is missing or empty. The TOKEN variable now contains the JWT returned by registration; keep it out of source control and logs.
Send the token in the exact header format required by the contract: Authorization: Token <jwt>.
curl --fail-with-body --silent --show-error \
--request GET "$BASE_URL/user" \
--header "Authorization: Token $TOKEN"The API returns 200 and a user object for the account you registered. Its username and email match the variables from the previous step, and its token is a non-empty string.
Use jq to check the identity returned by the protected request.
curl --fail-with-body --silent --show-error \
--request GET "$BASE_URL/user" \
--header "Authorization: Token $TOKEN" \
| jq --arg username "$USERNAME" 'if .user.username == $username and (.user.token | length) > 0 then "Conduit request succeeded" else error("unexpected user response") end'The command prints "Conduit request succeeded". You have completed the smallest authenticated workflow and can now use the authentication guide or choose an endpoint from the endpoint index.
If registration fails
If the server returns 409, generate a new username and email; the contract uses that status when an identity already exists. If it returns 422, check that the request contains all three required fields and that none is blank. A protected request without the header returns 401 with an error envelope; see Error envelope and HTTP status behavior.