---
title: "Generate a login token"
method: POST
path: "/auth/login-token"
tags: ["Auth"]
---

# Generate a login token

`POST /auth/login-token`

Generate a login token. If the visitor is already logged into a XenForo account, they will not be logged into the specified account. Only available to super user keys.

## Response `200`

OK

- object
  - `login_token` string
  - `login_url` string — Direct user to this URL to trigger a login
  - `expiry_date` integer — Unix timestamp of when the token expires. An error will be displayed if the token is expired or invalid

## Other responses

- `default` — Error

## Changes

- **2026-03-18** `e271d0e41f6d` — 2 breaking, 5 info
  - request body became required
  - removed the media type `application/json` from the request body
  - api operation id `post_auth_login_token` removed and replaced with `postAuthLoginToken`
  - the endpoint scheme security `XF-Api-Key` was added to the API
  - …3 more
- **2026-02-03** `fc0a40f3b859` — 4 warning, 5 info
  - the optional response header `XF-Latest-Api-Version` removed for the status `200`
  - the optional response header `XF-Request-User` removed for the status `200`
  - the optional response header `XF-Request-User-Extras` removed for the status `200`
  - the optional response header `XF-Used-Api-Version` removed for the status `200`
  - …5 more

[Change history](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/changes/auth/login-token/post.md)

---

[API](https://skmtc.dev/xenforo-ltd/apis/xenforo-api.md) · [All operations](https://skmtc.dev/xenforo-ltd/apis/xenforo-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/xenforo-ltd/xenforo-api/revisions/b15eba33657a/schema)
