# Authentication


The Intuizi API uses **bearer token** authentication. You exchange your Intuizi
Console credentials for a token, then send that token on every subsequent
request.

## Which token should I use?

There are three kinds, all sent the same way, as `Authorization: Bearer <token>`:

| Token | Where it comes from | How long it lasts | Use it for |
| --- | --- | --- | --- |
| **Login token** | [Log in](#get-a-token) with your console email and password | Until your next login, which replaces it. Logging out of the console or changing your password also ends it | Trying the API by hand |
| **API token** | **My Account > API Tokens** in the console, or [Create API Token](/api/v2/authentication#post-apiv2authapitoken) | One year. Logins and logouts leave it alone; a password change or a revoke ends it | Servers, scripts, CI, and the [Intuizi CLI](/cli), whose `intuizi auth login` creates one for you |
| **MCP token** | **My Account > MCP Tokens** in the console, or [Create MCP Token](/api/v2/authentication#post-apiv2authmcptoken) | One year, the same way | AI agents that run unattended. An agent you use yourself can [connect in one click](/mcp/getting-started) instead |

An API token works on every endpoint except the MCP server, which takes an MCP
token or a one-click sign-in. Up to 10 API tokens and 10 MCP tokens can be
active on an account at once.

## Get a token

`POST /api/v2/auth/login`

{{< tabs >}}

  {{< tab name="cURL" >}}
  ```bash
  curl -X POST "https://console.intuizi.com/api/v2/auth/login" \
    -H "Content-Type: application/json" \
    -H "Accept: application/json" \
    -d '{
      "email": "you@example.com",
      "password": "your-password"
    }'
  ```
  {{< /tab >}}

  {{< tab name="JavaScript" >}}
  ```javascript
  const res = await fetch("https://console.intuizi.com/api/v2/auth/login", {
    method: "POST",
    headers: {
      "Content-Type": "application/json",
      "Accept": "application/json",
    },
    body: JSON.stringify({ email: "you@example.com", password: "your-password" }),
  });
  const { data } = await res.json();
  const token = data.token;
  ```
  {{< /tab >}}

  {{< tab name="Python" >}}
  ```python
  import requests

  res = requests.post(
      "https://console.intuizi.com/api/v2/auth/login",
      headers={"Content-Type": "application/json", "Accept": "application/json"},
      json={"email": "you@example.com", "password": "your-password"},
  )
  token = res.json()["data"]["token"]
  ```
  {{< /tab >}}

  {{< tab name="PHP" >}}
  ```php
  $res = Http::acceptJson()->post(
      'https://console.intuizi.com/api/v2/auth/login',
      ['email' => 'you@example.com', 'password' => 'your-password']
  );
  $token = $res->json('data.token');
  ```
  {{< /tab >}}

{{< /tabs >}}

### Success response

```json
{
  "status": "success",
  "code": 200,
  "message": "Token generated successfully.",
  "data": {
    "token": "FxGrKXTS0iLgonnQZtELC0dWu73xslzHjGjaBVef"
  }
}
```

## Use the token

Send the token as a bearer token in the `Authorization` header on every
authenticated request:

```bash
curl "https://console.intuizi.com/api/v2/my-data/pois/segments/index" \
  -H "Authorization: Bearer FxGrKXTS0iLgonnQZtELC0dWu73xslzHjGjaBVef" \
  -H "Accept: application/json"
```

Failed requests use the shared error envelope - see [Errors](/concepts/errors).

## API tokens

> **Login tokens rotate.** Each successful login deletes the account's
> previous login token - one live login token per account - and the token is
> also revoked when the user logs out of the console. For CLI sessions, CI
> pipelines, and any long-lived integration, use an [API token](/api/v2/authentication#post-apiv2authapitoken)
> instead: API tokens are not rotated by logins and survive logout.

See [Create API Token](/api/v2/authentication#post-apiv2authapitoken) in the
API v2 reference for the full request/response detail, and [Revoke API
Tokens](/api/v2/authentication#post-apiv2authapitokenrevoke) to invalidate
them. API tokens are managed under **My Account > API Tokens** in the
console.
