# Auth (signup & sessions)

Most developers only need an API key from the dashboard. These endpoints are for building your own sign-in flow, or for automation.

## `POST /auth/signup` - public

Create a free account and receive a session **and** a first API key.

```bash
curl -X POST -H "Content-Type: application/json" \
  -d '{"email": "you@example.com", "password": "at-least-8-chars"}' \
  "https://api.pakdatahub.com/auth/signup"
```

```json
{ "success": true, "plan": "free", "session_token": "...", "api_key": "pk_live_...",
  "note": "store this key now - it is shown only once" }
```

The key is also emailed to you.

| Error | When |
|---|---|
| `409` | An account already exists for this email |
| `422` | Invalid email, or a password shorter than 8 characters |
| `429` | Too many signups from this network today |

## `POST /auth/login` - public

Body `{ "email", "password" }` returns `{ "success": true, "session_token": "..." }`. Wrong credentials return `401`.

## `POST /auth/logout`

Body `{ "session_token": "..." }` invalidates the session.

## `POST /auth/change-password` (key required) / session

Body `{ "current_password", "new_password" }`. A wrong current password returns `401`; a new password under 8 characters returns `422`.

## `POST /auth/set-password` - public

For buyers who paid before creating a password. Body `{ "token", "password" }`, where the `token` is the one-time signup token from the post-checkout `/welcome?token=` redirect. It only works while the account has no password yet (otherwise `409`), and it returns a session.

## Google sign-in - public

- `GET /auth/google/config` returns `{ "enabled": true }`.
- `GET /auth/google/start` redirects to Google's consent screen.
- `GET /auth/google/callback` signs you in by **verified** Google email (creating the account if needed) and redirects to `https://pakdatahub.com/auth/callback#session=<token>`.

## Using a session token

Send `X-Session-Token: <token>` to the account endpoints: [`/v1/account`, `/v1/keys`](https://pakdatahub.com/docs/api-account-keys.md), [`/v1/usage`](https://pakdatahub.com/docs/api-usage.md), [`/v1/webhooks`](https://pakdatahub.com/docs/api-webhooks.md) and `/v1/billing/portal`. Sessions last 30 days. Data endpoints need an API key.

---
Source: https://pakdatahub.com/docs/api-auth - PakDataHub docs index: https://pakdatahub.com/docs/llms.txt
