---
title: "Changes to Generate a login token"
method: POST
path: "/auth/login-token"
---

# Changes to Generate a login token

`POST /auth/login-token`

> Every recorded change to this endpoint, newest first.

## Timeline

Changed in 2 of 7 revisions.

- **2026-03-18** `e271d0e41f6d` — 2 breaking, 5 info
- **2026-02-03** `fc0a40f3b859` — 4 warning, 5 info

## Changes

- **2026-03-18** `e271d0e41f6d` — 2 breaking, 5 info
  - request body became required
  - removed the media type `application/json` from the request body
  - api operation id `post_auth_login_token` removed and replaced with `postAuthLoginToken`
  - the endpoint scheme security `XF-Api-Key` was added to the API
  - the endpoint scheme security `XF-OAuth2` was added to the API
  - added the new optional `header` request parameter `XF-Api-User` to all path's operations
  - added the new optional `query` request parameter `api_bypass_permissions` to all path's operations
- **2026-02-03** `fc0a40f3b859` — 4 warning, 5 info
  - the optional response header `XF-Latest-Api-Version` removed for the status `200`
  - the optional response header `XF-Request-User` removed for the status `200`
  - the optional response header `XF-Request-User-Extras` removed for the status `200`
  - the optional response header `XF-Used-Api-Version` removed for the status `200`
  - api operation id `postAuthLoginToken` removed and replaced with `post_auth_login_token`
  - the endpoint scheme security `XF-Api-Key` was removed from the API
  - the endpoint scheme security `XF-OAuth2` was removed from the API
  - request body became optional
  - added the media type `application/json` to the request body

---

[Operation](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/docs/auth/login-token/post.md) · [API](https://skmtc.dev/xenforo-ltd/apis/xenforo-api.md) · [Page](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/changes/auth/login-token/post)
