Auth endpoints
The REST authentication controller exposes the endpoints used for login, registration, verification, password reset, and OAuth.
Endpoints
Section titled “Endpoints”| Method | Path | Guard | Description |
|---|---|---|---|
POST |
/api/v1/authentication/login |
LocalGuard |
Authenticates and creates a session. |
POST |
/api/v1/authentication/register |
— | Registers a user and queues a verification email. |
POST |
/api/v1/authentication/logout |
SessionAuthGuard |
Destroys the current session. |
POST |
/api/v1/authentication/resend-verification |
— | Resends the verification email. |
POST |
/api/v1/authentication/verify-email |
— | Verifies the email with the OTP code. |
POST |
/api/v1/authentication/forgot-password |
— | Sends a password reset email. |
POST |
/api/v1/authentication/reset-password |
— | Resets the password with a token. |
GET |
/api/v1/authentication/oauth/google |
OAuthGuard('google') |
Starts Google OAuth flow. |
GET |
/api/v1/authentication/oauth/google/callback |
OAuthGuard('google') |
OAuth callback that creates a session. |
Response format
Section titled “Response format”All successful responses are wrapped by the global response formatter:
{ "success": true, "timeStamp": "2025-...", "data": { ... }}Login and OAuth callback return the authenticated user inside data. The other endpoints return a message object.
Errors
Section titled “Errors”Errors are handled by HttpExceptionFilter and return a consistent JSON envelope:
{ "statusCode": 401, "message": "Session not found", "success": false, "timestamp": "2025-..."}Calling from a client
Section titled “Calling from a client”Make sure to include credentials on cross-origin requests so the session cookie is sent and stored:
fetch('/api/v1/authentication/login', { method: 'POST', credentials: 'include', headers: { 'Content-Type': 'application/json', 'X-Csrf-Token': csrfToken }, body: JSON.stringify({ email, password }),});For CSRF-protected POST requests, the client must read the CSRF cookie and send the token back in the X-Csrf-Token header (or whatever header name you configure in csrf-csrf).