Authentication

Sign up a new auth user

Changed on

Create a new end-user account. The project is determined from the anon key. Requires project-specific anon key in Authorization header.

Session-less: signup never issues a session. On success it returns a uniform acknowledgement (AuthSignupResponse) with no tokens; the client obtains a session with a subsequent POST /auth/signin. If email confirmation is enabled for the project, a confirmation email is sent and confirmation_required is true.

Anti-enumeration: a signup for an already-registered email returns the exact same 201 response as a fresh signup — it never returns 409 — so the response cannot be used to discover which emails are registered.

post/auth/signup

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/auth/signup
  • Auth: HTTP bearer

Request body

emailstring email required
passwordstring required

Password validated after NFC normalization against the policy returned by GET /auth/password-policy.

user_metadataobject

Response

Signup acknowledged (session-less). Returned identically for a new account and for an already-registered email (anti-enumeration).

confirmation_requiredboolean required

Whether the project requires email confirmation. Reflects project config only (identical for a new and an existing email), so it leaks nothing about account existence.

messagestring required

Human-readable acknowledgement.

Changes

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ○

      added the optional property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ○

      the request property's minLength was decreased from 6 to 0

    • ○

      added the non-success response with the status