Groove Restricted

Resolve this before you come in.

This desk keeps a single admission problem. It is exact. Rounding commentary, spaces, and separators are refused.

Ramanujan noticed that this value misses an integer by less than one part in a trillion. Write that integer.

Back to docs
API reference

Authentication

15 methods. Request fields, an example response, and notes on what comes back in data.

Base https://api.groove.com.na Updated October 2026
POST /api/auth/apple

Sign in or link an account with Apple.

Public

Request

ParameterInReq.Description
identity_tokenbodyYApple identity token from Sign in with Apple (min 1).
emailbodyNAccount email address (stored lowercase).
full_namebodyNOptional display name from Apple on first authorization (min 1, max 120).

Example body

{
  "identity_token": "{{appleIdentityToken}}",
  "email": "customer@privaterelay.appleid.com",
  "full_name": "Apple Customer"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/google

Sign in or link an account with Google.

Public

Request

ParameterInReq.Description
id_tokenbodyYGoogle ID token from the client SDK (min 1).

Example body

{
  "id_token": "{{googleIdToken}}"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/login

Sign in with email and password and receive access tokens.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).
passwordbodyYAccount password (min 1).

Example body

{
  "email": "{{adminEmail}}",
  "password": "{{adminPassword}}"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {
    "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
    "refreshToken": "rt_8f3c2a1b9e...",
    "expiresIn": 3600,
    "user": {
      "id": "66f0a1b2c3d4e5f678901234",
      "name": "Pat Fan",
      "email": "pat@example.com",
      "roles": [
        "customer"
      ]
    }
  }
}

Response data

Wrapped in the standard envelope (status, success, data, …). See the introduction for envelope fields.

FieldDescription
data.accessTokenJWT access token. Send as Authorization: Bearer.
data.refreshTokenLong-lived refresh token for /api/auth/refresh.
data.expiresInAccess token lifetime in seconds.
data.userObject. Nested fields follow.
data.user.idResource identifier (Mongo ObjectId string).
data.user.nameHuman-readable name.
data.user.emailEmail address.
data.user.rolesArray. Element shape shown when sample includes objects.
POST /api/auth/logout

Revoke the refresh token and end the session.

Public

Request

ParameterInReq.Description
refreshTokenbodyYOpaque refresh token from login or the previous refresh call (min 1).

Example body

{
  "refreshToken": "{{refreshToken}}"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

GET /api/auth/me

Return the signed-in user profile.

Bearer token

Request

No body or query parameters. Path values above, if any, are enough.

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {
    "id": "66f0a1b2c3d4e5f678901234",
    "name": "Pat Fan",
    "email": "pat@example.com",
    "roles": [
      "customer"
    ],
    "phone": "+264811234567"
  }
}

Response data

Wrapped in the standard envelope (status, success, data, …). See the introduction for envelope fields.

FieldDescription
data.idResource identifier (Mongo ObjectId string).
data.nameHuman-readable name.
data.emailEmail address.
data.rolesArray. Element shape shown when sample includes objects.
data.phonePhone number when present on the profile.
POST /api/auth/password-reset/complete

Set a new password after reset verification.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).
resetTokenbodyYShort-lived token returned after a successful password-reset verify step (min 32, max 256).
passwordbodyYAccount password (min 8, max 128).

Example body

{
  "email": "user@example.com",
  "resetToken": "\u2026",
  "password": "\u2022\u2022\u2022\u2022\u2022\u2022\u2022\u2022"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/password-reset/request

Start a password reset for an email address.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).

Example body

{
  "email": "user@example.com"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/password-reset/verify

Verify a password-reset code.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).
codebodyYOne-time verification or OTP code (length 6).

Example body

{
  "email": "user@example.com",
  "code": "\u2026"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/refresh

Exchange a refresh token for a new access token.

Public

Request

ParameterInReq.Description
refreshTokenbodyYOpaque refresh token from login or the previous refresh call (min 1).

Example body

{
  "refreshToken": "{{refreshToken}}"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {
    "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
    "refreshToken": "rt_rotated_token...",
    "expiresIn": 3600
  }
}

Response data

Wrapped in the standard envelope (status, success, data, …). See the introduction for envelope fields.

FieldDescription
data.accessTokenJWT access token. Send as Authorization: Bearer.
data.refreshTokenLong-lived refresh token for /api/auth/refresh.
data.expiresInAccess token lifetime in seconds.
POST /api/auth/register/admin

Create an admin user.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).
passwordbodyYAccount password (min 8, max 128).
namebodyYDisplay name (min 2, max 120).
titlebodyNJob title shown on the admin profile (max 80).
bootstrapSecretbodyNOne-time bootstrap secret for creating the first admin.
assignedTierbodyNAdmin tier: analyst, support, admin, or super_admin.

Example body

{
  "email": "admin2@groove.na",
  "password": "SecureAdminPass123!",
  "name": "Second Admin",
  "title": "Support"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/register/customer

Create a fan (customer) account.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).
passwordbodyYAccount password (min 8, max 128).
firstNamebodyYGiven name (min 1, max 80).
lastNamebodyYFamily name (min 1, max 80).
phonebodyNContact mobile number in international or local form (min 4, max 32).

Example body

{
  "email": "{{customerEmail}}",
  "password": "{{customerPassword}}",
  "firstName": "UAT",
  "lastName": "Customer",
  "phone": "+264811234567"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/register/merchant

Create a merchant account.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).
passwordbodyYAccount password (min 8, max 128).
namebodyYDisplay name (min 2, max 120).
businessNamebodyYMerchant business / trading name (min 2, max 200).
stallNamebodyNStall label shown on the floor and in reports (max 100).
phonebodyNContact mobile number in international or local form (min 4, max 32).

Example body

{
  "email": "{{merchantEmail}}",
  "password": "{{merchantPassword}}",
  "name": "UAT Merchant",
  "businessName": "UAT Stall",
  "stallName": "Food",
  "phone": "+264811234569"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/register/organiser

Create an organiser account.

Public

Request

ParameterInReq.Description
namebodyYDisplay name (min 2, max 120).
orgNamebodyYLegal or trading name of the organiser business (min 2, max 200).
emailbodyYAccount email address (stored lowercase).
phonebodyNContact mobile number in international or local form (min 4, max 32).
passwordbodyYAccount password (min 8, max 128).

Example body

{
  "name": "UAT Organiser",
  "orgName": "Groove UAT Org",
  "email": "{{organiserEmail}}",
  "phone": "+264811234568",
  "password": "{{organiserPassword}}"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/resend-verification

Send a fresh email verification code.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).

Example body

{
  "email": "{{customerEmail}}"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

POST /api/auth/verify-email

Confirm an email address with a verification code.

Public

Request

ParameterInReq.Description
emailbodyYAccount email address (stored lowercase).
codebodyYOne-time verification or OTP code (length 6).

Example body

{
  "email": "{{customerEmail}}",
  "code": "123456"
}

Example response

{
  "status": "success",
  "success": true,
  "statusCode": "00000",
  "message": "OK",
  "shortMessage": "SUCCESS",
  "timestamp": "2026-10-10T21:00:00.000Z",
  "requestId": "a1b2c3d4e5f6g7h8",
  "data": {}
}

Response data

Success returns the standard envelope. data holds the payload for this method — confirm the shape in your client when integrating.

Lock this page again

Authentication · 15 methods · October 2026