---
title: "Start customer login"
method: POST
path: "/v3/stores/{store_id}/public/auth/login"
tags: ["Customer Auth"]
---

# Start customer login

`POST /v3/stores/{store_id}/public/auth/login`

Public storefront endpoint. If the store can complete login directly, a successful credential check returns customer JWT tokens. If the store requires OTP, a successful credential check sends the one-time code and returns a message object so the frontend can show the OTP entry step.

## Path parameters

- `store_id` string, required

## Headers

- `X-Scalev-Storefront-Api-Key` string, required

## Request body

- CustomerLoginRequest
  - `email` string, email, required
  - `password` string, required
  - `login_as` 'customer' | 'owner'

## Response `200`

Customer login tokens, or an OTP challenge message when the store requires OTP.

- union
  - CustomerAuthTokenResponseBody
    - `access` string, required — Customer access JWT. Send it as `Authorization: Bearer <token>` to `/v3/stores/{store_id}/customers/me/*`.
    - `refresh` string, required — Refresh token for `POST /v3/stores/{store_id}/public/auth/jwt/refresh`.
    - `token_type` 'Bearer', required — Token type to use in the `Authorization` header.
    - `expires_in` integer, required — Access token lifetime in seconds.
    - `refresh_expires_in` integer, required — Refresh token lifetime in seconds. Refresh tokens rotate on every refresh and are single-use.
    - `store_unique_id` string, nullable — Public store unique ID returned by some OTP verification responses.
  - CustomerLoginOtpChallengeResponseBody
    - `message` string, required — OTP challenge message. Show the OTP entry UI and continue with `POST /v3/stores/{store_id}/public/auth/otp/verify`.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized

---

[API](https://skmtc.dev/scalev/apis/nexus-commerce-api.md) · [All operations](https://skmtc.dev/scalev/apis/nexus-commerce-api/llms.txt) · [OpenAPI document](https://skmtc.dev/scalev/apis/nexus-commerce-api/revisions/03e66641bebd?raw)
