Get the logged-in user and account
Authorization
sessionAuth A session token for an existing account, obtained from POST /auth/login (see the Authentication endpoints) - not an API key. Endpoints marked with this scheme reject API key callers outright, regardless of what that key is granted. Outside the Authentication endpoints themselves, everything requiring this scheme manages dashboard resources (schedules, rules, grants, keys, device configuration) and mirrors what a human does in the Nexalware web app - it is not meant to be automated by a third-party integration the way the Device Control endpoints are.
In: header
Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/api/v1/auth/me"{ "userId": "string", "email": "string", "name": "string", "emailVerified": true, "accountId": "string", "accountName": "string", "plan": "string", "role": "string", "deviceCount": 0, "hasPassword": true, "hasGoogleAuth": true, "hasGithubAuth": true}Exchange a refresh token for a new session POST
Call this when the access token expires (every 15 minutes) rather than asking the user to log in again. The refresh token itself rotates on every use - store the new one.
Log in and obtain a session token POST
Exchanges an existing account's email/password for a token pair. This is how a third-party client (your own app, a custom login screen, a CLI) authenticates a user directly, without going through the Nexalware dashboard UI. Creating a *new* account is dashboard-only (nexalware.com/sign-up) and is not exposed here - this endpoint only signs in an account that already exists.