Skip to content
Authentication
.md

Authentication

The Intuizi API uses bearer token authentication. You exchange your Intuizi Console credentials for a token, then send that token on every subsequent request.

Which token should I use?

There are three kinds, all sent the same way, as Authorization: Bearer <token>:

TokenWhere it comes fromHow long it lastsUse it for
Login tokenLog in with your console email and passwordUntil your next login, which replaces it. Logging out of the console or changing your password also ends itTrying the API by hand
API tokenMy Account > API Tokens in the console, or Create API TokenOne year. Logins and logouts leave it alone; a password change or a revoke ends itServers, scripts, CI, and the Intuizi CLI, whose intuizi auth login creates one for you
MCP tokenMy Account > MCP Tokens in the console, or Create MCP TokenOne year, the same wayAI agents that run unattended. An agent you use yourself can connect in one click instead

An API token works on every endpoint except the MCP server, which takes an MCP token or a one-click sign-in. Up to 10 API tokens and 10 MCP tokens can be active on an account at once.

Get a token

POST /api/v2/auth/login

curl -X POST "https://console.intuizi.com/api/v2/auth/login" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json" \
  -d '{
    "email": "you@example.com",
    "password": "your-password"
  }'

Success response

{
  "status": "success",
  "code": 200,
  "message": "Token generated successfully.",
  "data": {
    "token": "FxGrKXTS0iLgonnQZtELC0dWu73xslzHjGjaBVef"
  }
}

Use the token

Send the token as a bearer token in the Authorization header on every authenticated request:

curl "https://console.intuizi.com/api/v2/my-data/pois/segments/index" \
  -H "Authorization: Bearer FxGrKXTS0iLgonnQZtELC0dWu73xslzHjGjaBVef" \
  -H "Accept: application/json"

Failed requests use the shared error envelope - see Errors.

API tokens

Login tokens rotate. Each successful login deletes the account’s previous login token - one live login token per account - and the token is also revoked when the user logs out of the console. For CLI sessions, CI pipelines, and any long-lived integration, use an API token instead: API tokens are not rotated by logins and survive logout.

See Create API Token in the API v2 reference for the full request/response detail, and Revoke API Tokens to invalidate them. API tokens are managed under My Account > API Tokens in the console.