Comfort Oak

Authentication

Two guards, two login paths. Customers and staff never share tokens. Send Authorization: Bearer {token} on protected routes.

Customer

Public auth under /api/v1/auth/*. After login, use the token for account, addresses, orders, and wishlist.

POST /api/v1/auth/register
POST /api/v1/auth/login
POST /api/v1/auth/forgot-password
POST /api/v1/auth/reset-password

POST /api/v1/auth/logout   # bearer
GET  /api/v1/auth/me       # bearer

Example login

curl -X POST https://api.comfortoak.com/api/v1/auth/login \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"email":"meera.k@example.com","password":"comfortoak"}'

Staff

Admin auth under /api/v1/admin/auth/*. Sanctum tokens plus Spatie permissions gate each resource group.

POST /api/v1/admin/auth/login
POST /api/v1/admin/auth/forgot-password
POST /api/v1/admin/auth/reset-password

POST  /api/v1/admin/auth/logout   # bearer
GET   /api/v1/admin/auth/me       # bearer
PATCH /api/v1/admin/auth/profile  # bearer

Example staff login

curl -X POST https://api.comfortoak.com/api/v1/admin/auth/login \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"email":"asha@comfortoak.com","password":"comfortoak"}'
Seeded local accounts use password comfortoak — staff asha@comfortoak.com, customer meera.k@example.com.

Using the token

Authorization: Bearer {token}
Accept: application/json

In the OpenAPI explorer, open Authenticate and paste a bearer token to try protected routes.