---
title: "User login"
method: POST
path: "/users/actions/login"
tags: ["Users"]
---

# User login

`POST /users/actions/login`

User login to external application.
⚠️ Endpoint is available only in the Enterprise interface.

## Headers

- `Accept-Language` string

## Request body

- object
  - `user_external_application_id` string — ID of an external application where user wants to be logged in from resource [customer-external-applications](https://carecloud.readme.io/reference/customer-external-applications).
  - `login` string — Login name of user in CareCloud.
  - `password` string, password — The CareCloud user password.

## Response `200`

OK

- object
  - `data` object
    - `bearer_token` string — Authentication bearer token for an user. Token can be used for authentication in REST API with Bearer Authentication (more information about it [here](https://carecloud.readme.io/reference/authorization#bearerauth)).
    - `valid_to` string — Date and time (local time zone of the project) of the token validity. *(YYYY-MM-DD HH:MM:SS)*
    - `user` User — Information about logged in user.
      - `user_id` string — The unique ID of the user.
      - `login` string, required — Login ID of the user.
      - `first_name` string, required — First name of the user.
      - `last_name` string, required — Last name of the user.
      - `email` string, required — Email of the user.
      - `phone` string — Phone number of the user with international prefix (420000000).
      - `user_role_ids` string[] — The list of the user role IDs.
      - `store_id` string — The unique ID of user's original store. [GET /stores](https://carecloud.readme.io/reference/getstores)
      - `last_login` string — Timestamp of the last user login. Format: `YYYY-MM-DD HH:MM:SS`. All times are in the local timezone.

## Other responses

- `201` — Created
- `400` — Bad input parameter. The response body's `error.error_data.invalid_params[]` array lists the parameters that caused the failure, each carrying a `reason` code. See the `BadRequestErrorBody` schema for the generic reason taxonomy. Operations with domain-specific business rules document additional reasons at the operation level.
- `403` — The client does not exist or the client tried to access an unauthorized property or resource.
- `404` — The resource was not found.
- `405` — The resource does not support the specified HTTP method.
- `429` — Too many requests - more than the resource limit.
- `500` — Server is not working as expected.
- `503` — Temporary state when the service is temporarily unavailable, overloaded or there is a maintenance window.

---

[API](https://skmtc.net/crmcarecloud/apis/rest-api-reference.md) · [All operations](https://skmtc.net/crmcarecloud/apis/rest-api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/crmcarecloud/rest-api-reference/revisions/329c06dbf8d9/schema)
