Authentication
Two guards, two login paths. Customers and staff never share tokens.
Send Authorization: Bearer {token} on protected routes.
Customer
Public auth under /api/v1/auth/*. After login, use the token for account, addresses, orders, and wishlist.
POST /api/v1/auth/register POST /api/v1/auth/login POST /api/v1/auth/forgot-password POST /api/v1/auth/reset-password POST /api/v1/auth/logout # bearer GET /api/v1/auth/me # bearer
Example login
curl -X POST https://api.comfortoak.com/api/v1/auth/login \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"email":"meera.k@example.com","password":"comfortoak"}'
Staff
Admin auth under /api/v1/admin/auth/*. Sanctum tokens plus Spatie permissions gate each resource group.
POST /api/v1/admin/auth/login POST /api/v1/admin/auth/forgot-password POST /api/v1/admin/auth/reset-password POST /api/v1/admin/auth/logout # bearer GET /api/v1/admin/auth/me # bearer PATCH /api/v1/admin/auth/profile # bearer
Example staff login
curl -X POST https://api.comfortoak.com/api/v1/admin/auth/login \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"email":"asha@comfortoak.com","password":"comfortoak"}'
Seeded local accounts use password
comfortoak —
staff asha@comfortoak.com, customer meera.k@example.com.
Using the token
Authorization: Bearer {token}
Accept: application/json
In the OpenAPI explorer, open Authenticate and paste a bearer token to try protected routes.