# Login user via api and get token

**URL:** <https://forum.gitea.com/t/login-user-via-api-and-get-token/561>\
**Category:** API/SDK/Tea/HelmChart/Terraform\
**Created:** [September 12, 2018, 9:32am UTC](https://forum.gitea.com/t/login-user-via-api-and-get-token/561 "2018-09-12T09:32:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmls](https://avatars.discourse-cdn.com/v4/letter/j/b2d939/32.png) [@jmls](https://forum.gitea.com/u/jmls)\
**Post date:** [September 12, 2018, 9:32am UTC](https://forum.gitea.com/t/login-user-via-api-and-get-token/561/1 "2018-09-12T09:32:13Z")

</div>

I am trying to use gitea as a backend system, and as such want to login with username and password via the api and then use a token for any further api requests

I must be blind - I just can’t see any documented api for login. I see that there is a “basic” auth but I don’t want to use that in case the headers get logged.

The login POST’s to /user/login - I have tried that, but no token is returned

any insight would be appreciated 😉

---

<div class="post-metadata">

**Author:** ![techknowlogick](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/techknowlogick/32/4706_2.png) [@techknowlogick](https://forum.gitea.com/u/techknowlogick)\
**Post date:** [September 12, 2018, 3:43pm UTC](https://forum.gitea.com/t/login-user-via-api-and-get-token/561/2 "2018-09-12T15:43:14Z")

</div>

Here is the documentation on creating a token: [https://try.gitea.io/api/swagger#/user/userCreateToken](https://try.gitea.io/api/swagger#/user/userCreateToken) you must use username/pass via basic auth on that endpoint. Once you have a token you can use it an all other endpoints.

---

<div class="post-metadata">

**Author:** ![georg](https://avatars.discourse-cdn.com/v4/letter/g/9f8e36/32.png) [@georg](https://forum.gitea.com/u/georg)\
**Post date:** [March 20, 2019, 6:44pm UTC](https://forum.gitea.com/t/login-user-via-api-and-get-token/561/3 "2019-03-20T18:44:58Z")

</div>

I can’t execute it on Gitea 1.7.4

Using **Swagger UI** I try to create a token for an existing user:

```
username = alice
password = 123456

```

**Basic authorization** : Done

**Execute** for ‘alice’ now:

`curl -X POST "https://localhost:3000/api/v1/users/alice/tokens" -H "accept: application/json" -H "authorization: Basic bmlrb2xheToxMjM0NTY=" -H "Content-Type: application/json" -d "{ \"name\": \"token_name\"}"`

**Server response** :

`Code: 401 Error: Unauthorized`

I tried Basic auth as an administrator but got the same error.

What did I miss here? 🙁

---

<div class="post-metadata">

**Author:** ![georg](https://avatars.discourse-cdn.com/v4/letter/g/9f8e36/32.png) [@georg](https://forum.gitea.com/u/georg)\
**Post date:** [March 20, 2019, 7:10pm UTC](https://forum.gitea.com/t/login-user-via-api-and-get-token/561/4 "2019-03-20T19:10:30Z")

</div>

Seems, it’s works only as:

```
curl -X POST "https://alice:123456@localhost:3000/api/v1/users/alice/tokens" -H "accept: application/json" -H "Content-Type: application/json" -d "{  
	\"name\": \"token_name\"
}"

```

Executed it via console.

---

<div class="post-metadata">

**Author:** ![manwe](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/manwe/32/1768_2.png) [@manwe](https://forum.gitea.com/u/manwe)\
**Post date:** [October 29, 2021, 5:43pm UTC](https://forum.gitea.com/t/login-user-via-api-and-get-token/561/5 "2021-10-29T17:43:05Z")

</div>

Came across this and one reason could be that  
your curl example has username “nikolay” and not “alice” inside the basic auth string.
