Authentication
Session tokens
Log in with email and password to receive a JWT session token:
curl -X POST http://YOUR_TODOLESS_HOST:7070/api/collections/users/auth-with-password \
-H "Content-Type: application/json" \
-d '{"identity": "demo@example.com", "password": "correct-horse-battery"}'
The response is a PocketBase auth response: a token (the JWT) and a record (your user profile). Send the token as a bearer credential:
curl http://YOUR_TODOLESS_HOST:7070/api/entries \
-H "Authorization: Bearer YOUR_SESSION_TOKEN"
In browser contexts the session may also be carried by the pb_token cookie; server-to-server clients should use the Authorization header.
Personal API tokens
Family administrators can issue personal API tokens for family members. A token:
- starts with the prefix tl_,
- has explicit permission scopes (for example tasks:read, tasks:write, groceries:read, groceries:write, calendar:read, calendar:write),
- can be enabled, disabled (revoked) and given an expiry date.
- is shown to its owner exactly once at creation — treat it like a password.
Use it exactly like a session token:
curl http://YOUR_TODOLESS_HOST:7070/api/entries \
-H "Authorization: Bearer tl_YOUR_API_TOKEN"
⚠️ Token administration (creating, listing, revoking) is an administrative capability of the API, performed by family administrators. This website does not create, display or revoke tokens.
Errors
Authenticated endpoints return 401 when the credential is missing or invalid, and 403 when the credential is valid but lacks the required permission or scope.