Tessera docs

Launch Tessera

Launch

Authentication

Create token

Exchange credentials for an access token and a refresh token.

POST

/v1/auth/token

Signs a user in with email and password, or exchanges an OAuth code, and returns a short-lived access token together with a refresh token.

Request body

grant_typestringrequired

One of password or authorization_code.

emailstringoptional

Required when grant_type is password.

passwordstringoptional

Required when grant_type is password.

codestringoptional

The OAuth code, required for authorization_code.

Response fields

access_tokenstringrequired

JWT valid for 15 minutes.

refresh_tokenstringrequired

Opaque token valid for 30 days.

expires_inintegerrequired

Seconds until the access token expires.

userobjectrequired

The signed-in user: id, email, name.

Errors

400invalid_grant

The credentials or code are wrong.

429rate_limited

Too many requests. Retry after the number of seconds in Retry-After.

curl --request POST \  --url https://api.tessera.dev/v1/auth/token \  --header "Content-Type: application/json" \  --data '{"grant_type":"password","email":"ada@acme.dev","password":"••••••••"}'
{  "access_token": "eyJhbGciOiJIUzI1NiIs…",  "refresh_token": "rt_9Xk2mP4qLw8",  "expires_in": 900,  "user": {    "id": "usr_42",    "email": "ada@acme.dev",    "name": "Ada Park"  }}

© 2026 Tessera, Inc.

Support

Status

Create a free website with Framer, the website builder loved by startups, designers and agencies.