# How to login and get the API token with username and password?

**URL:** <https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483>\
**Category:** Cockpit v2\
**Created:** [September 12, 2022, 9:57am UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483 "2022-09-12T09:57:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jamo](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/jamo/32/1117_2.png) [@Jamo](https://discourse.getcockpit.com/u/Jamo)\
**Post date:** [September 12, 2022, 9:57am UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/1 "2022-09-12T09:57:24Z")

</div>

Hey there 👋

I’m currently working on a frontend project which will feature user logins which will be required to use the application. So far so easy.

I want to use Cockpit’s (v2) user authentication and role management in order to avoid having to code my own login API.  
So I’ve just opened my Dev Tools, logged into my Cockpit Backend, and saw that there’s a request going to `/auth/check` which has a request body like this:

```json
{
    "auth": {
        "user": "USERNAME",
        "password": "PASSWORD"
    },
    "csrf": "TOKEN"
}

```

Now I’m wondering where I’m supposed to get the value for the CSRF token from.  
As far as I can see, there’s no endpoint which I could use to get a token from Cockpit.

CSRF tokens are meant to identify client sessions and are therefore unique for every session, don’t they?

My question might be stupid - I know. I’m sorry if that’s the case. But I’m not really deep into CSRF and PHP, so this is new to me.

Thanks for everyone who’s helping me here 🙏

Have a great day 🙂

---

<div class="post-metadata">

**Author:** ![Jamo](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/jamo/32/1117_2.png) [@Jamo](https://discourse.getcockpit.com/u/Jamo)\
**Post date:** [November 21, 2022, 8:50am UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/2 "2022-11-21T08:50:06Z")

</div>

Just wanted to bring this back up hoping that anyone has an idea 🙂

---

<div class="post-metadata">

**Author:** ![Jamo](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/jamo/32/1117_2.png) [@Jamo](https://discourse.getcockpit.com/u/Jamo)\
**Post date:** [November 21, 2022, 10:10am UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/3 "2022-11-21T10:10:13Z")

</div>

I can see that the Token gets generated within the Csrf Helper at `/modules/App/Helper/Csrf.php` and used in the Vue `login()` method in `/modules/App/views/auth/login.php`

---

<div class="post-metadata">

**Author:** ![letima](https://avatars.discourse-cdn.com/v4/letter/l/9e8a1a/32.png) [@letima](https://discourse.getcockpit.com/u/letima)\
**Post date:** [December 22, 2022, 12:50pm UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/4 "2022-12-22T12:50:55Z")

</div>

Did you found a solution to your problem?

---

<div class="post-metadata">

**Author:** ![gezeichnet](https://avatars.discourse-cdn.com/v4/letter/g/e19b73/32.png) [@gezeichnet](https://discourse.getcockpit.com/u/gezeichnet)\
**Post date:** [March 27, 2023, 7:06pm UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/5 "2023-03-27T19:06:15Z")

</div>

I wrote a small plugin which allows registering and logging in via API. If you are interested, contact me.

---

<div class="post-metadata">

**Author:** ![Cryptospy](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/cryptospy/32/1169_2.png) [@Cryptospy](https://discourse.getcockpit.com/u/Cryptospy)\
**Post date:** [April 4, 2023, 7:36pm UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/6 "2023-04-04T19:36:00Z")

</div>

Hey , i would like to hear more

---

<div class="post-metadata">

**Author:** ![gezeichnet](https://avatars.discourse-cdn.com/v4/letter/g/e19b73/32.png) [@gezeichnet](https://discourse.getcockpit.com/u/gezeichnet)\
**Post date:** [April 5, 2023, 8:12am UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/7 "2023-04-05T08:12:52Z")

</div>

Two simple methods, for Register and Login via API. These are only the basics, how to authenticate. I used the Cockpit internal Methods, only added the Endpoints.  
Note: returning the whole user-object is not the best solution, you need to think about a cleanup of this data.

Register

```auto
    $restApi->addEndPoint('/auth/register', [
        /**
         * @OA\POST(
         * path="/auth/register",
         * tags={"auth"},
         * @OA\Response(response="200", description="Register via API")
         * )
         */
        'POST' => function($params, $app) {
            $userController = new \System\Controller\Users($app, ['action' => 'user', 'params' => $params]);

            error_reporting(0); // there is a, not avoidable, warning in create. to get clean output, disable error reporting
            $user = $userController->save();
            return $user
        },
    ]);

```

Login

```auto

    $restApi->addEndPoint('/auth/check', [
        /**
         * @OA\POST(
         * path="/auth/check",
         * tags={"auth"},
         * @OA\Response(response="200", description="Login via API")
         * )
         */
        'POST' => function($params, $app) {
            $user = $app->helper('auth')->authenticate($app->request->param('auth'));

            return $user
        }
    ]);

```

---

<div class="post-metadata">

**Author:** ![xiclica](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/xiclica/32/1382_2.png) [@xiclica](https://discourse.getcockpit.com/u/xiclica)\
**Post date:** [September 6, 2023, 3:34pm UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/8 "2023-09-06T15:34:54Z")

</div>

I make a small update hoping that it will be useful for those who are in v2, the same endpoint returning a JWT

```auto
 //AUTH
    $restApi->addEndPoint('/auth/check', [
        
        
        'POST' => function($params, $app) {
            $data = [
                'user' => $app->param('username'),
                'email' => $app->param('email'),
                'password' => $app->param('password')
            ];
            
            $user = $this->helper('auth')->authenticate($data);
            $newJWT = $this->helper('jwt')->create($user);
            return array( "jwt" => $newJWT );

           
        }
    ]);

```

I have put this in the path: **/modules/Content/api.php**

---

<div class="post-metadata">

**Author:** ![michka](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/michka/32/1408_2.png) [@michka](https://discourse.getcockpit.com/u/michka)\
**Post date:** [November 24, 2023, 3:49pm UTC](https://discourse.getcockpit.com/t/how-to-login-and-get-the-api-token-with-username-and-password/2483/9 "2023-11-24T15:49:31Z")

</div>

Ahoi, this is not yet published in the Cockpit-HQ, right? Is it planned to be? @artur

I put this for local testing in the api.php but the /auth/check is not known (404). Any tipps how to make this work?

Thanks a lot.
