Skip to main content
GET
Verify a magic link and start a session
This endpoint is called when the customer clicks the magic link in their email. It verifies the token and returns a session for portal access.

Query Parameters

Example Request

Response

The 7-day session is delivered only as the httpOnly portal_session cookie (plus a readable portal_csrf double-submit cookie) — it is never in the JSON body. Send subsequent portal requests with credentials: "include".
Prefer POST /portal/auth/verify: the token travels in the request body instead of the URL, so it does not end up in Referer headers, browser history, or access logs.
Magic link tokens are single-use and expire after 15 minutes. If the token is invalid or expired, a 401 error is returned.

Authorizations

Authorization
string
header
required

Query Parameters

token
string
required

Response

Session created (cookie set).

message
string