> This page is for Taurus PROTECT, version v3.44.
> For other versions, use one of these documentation indexes:
> - v3.58 (default): https://taurushq.ferndocs.com/protect-capital/v3.58/llms.txt
> - v3.56: https://taurushq.ferndocs.com/protect-capital/v3.56/llms.txt
> - v3.54: https://taurushq.ferndocs.com/protect-capital/v3.54/llms.txt
> - v3.52: https://taurushq.ferndocs.com/protect-capital/v3.52/llms.txt
> - v3.50: https://taurushq.ferndocs.com/protect-capital/v3.50/llms.txt
> - v3.48: https://taurushq.ferndocs.com/protect-capital/v3.48/llms.txt
> - v3.46: https://taurushq.ferndocs.com/protect-capital/v3.46/llms.txt
> - v3.44: https://taurushq.ferndocs.com/protect-capital/v3.44/llms.txt
> - v3.42: https://taurushq.ferndocs.com/protect-capital/v3.42/llms.txt
> - v3.40: https://taurushq.ferndocs.com/protect-capital/v3.40/llms.txt
> - v3.38: https://taurushq.ferndocs.com/protect-capital/v3.38/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://taurushq.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://taurushq.ferndocs.com/_mcp/server.

# Bearer Authentication

## Basic Description

Bearer Authentication uses JWTs with a default **validity of 30 minutes**. To obtain a JWT Bearer Authentication Token, you need to pass your Taurus-PROTECT credentials to the **api/rest/v1/authentication/token** endpoint as described in the examples below.

For the full documentation of this endpoint, please refer to the relevant [API documentation section](/protect-capital/v3.44/reference/authentication/authenticate) .

### Required Roles

TPUser

### Required Input Parameters

This is a POST method with the following json structure as input in the body of the call:

```json
{
  "email": "john@example.com",
  "password": "secret",
  "totp": "12345",
  "username": "john_example" 
}
```

**password**:  This is a required parameter. The value of this field is the clear text password of the user determined by one of the options below.

Pick one of two ways to identify the user:\
**username**:  The username given to the user on creation.\
**email**: The email address of the user.\
If multi factor authentication is enabled for the user, use the **totp** parameter to set the one time token.

> **Note**
>
> **Preconditions**
>
> It is important to note that the user credentials required for this endpoint need to pre-exist on the system. You will not be able to perform this call without valid credentials on Taurus-PROTECT.

## Call Example

You can find a basic example in cURL below.\
Please note that you will need to update the `BASEURL` for the command to function.

**`cURL`**

```curl cURL
export BASEURL=https://taurus-protect-instance.com
curl --location '$BASEURL/api/rest/v1/authentication/token' \
--header 'Content-Type: application/json' \
--header 'Accept: application/json' \
--data-raw '{
  "email": "user1@bank.com",
  "password": "1234567896"
}'
```

This piece of code sends a POST request to  [https://your-protect-instance.example.com/api/rest/v1/authentication/token](https://your-protect-instance.example.com/api/rest/v1/authentication/token) with the JSON string in the request body.

> **Tip**
>
> **Call Result**
>
> A successful response for the POST call to create a wallet might look like this:

```json
{
    "result": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6MTEsImV4dGVybmFsVXNlcklEIjoidGVhbTFAYmFuay5jb20iLCJ0ZW5hbnRJRCI6MSwiY2FwaXRhbFRlbmFudElEIjoxLCJmaXJzdG5hbWUiOiJKb2huIiwibGFzdG5hbWUiOiJUMSIsInJvbGVzIjpbInByaWNldXBkYXRlciIsIndoaXRlbGlzdGVkYWRkcmVzc2NyZWF0b3IiLCJyZXF1ZXN0YXBwcm92ZXIiLCJhZG1pbnJlYWRvbmx5IiwidHB1c2VyIiwic3VwZXJhZG1pbnJlYWRvbmx5Iiwic2lnbmV0dXNlciIsInJlcXVlc3RjYW5jZWxlciIsInJlcXVlc3RjcmVhdG9yIiwiYWNjb3VudGNyZWF0b3IiLCJvcGVyYXRvciIsImF1ZGl0dmlld2VyIiwid2hpdGVsaXN0ZWRhZGRyZXNzYXBwcm92ZXIiLCJmaWxldXBsb2FkZXIiLCJmaWxlZG93bmxvYWRlciJdLCJlbWFpbCI6InRlYW0xQGJhbmsuY29tIiwidXNlcm5hbWUiOiJ0ZWFtMUBiYW5rLmNvbSIsImp3dF9yZW5ld2FibGVfYW1vdW50IjowLCJpc190b3RwX2VuYWJsZWQiOmZhbHNlLCJhdXRoX3N0YXR1cyI6IlNVQ0NFU1MiLCJsYXN0X2xvZ2luIjoiMjAyMy0wNC0xMVQxMjo1MToxNi4xNDk3NDQyMzJaIiwibG9nZ2VkX2luX3dpdGhfc3NvIjpmYWxzZSwia2V5IjoiIiwiZXhwIjoxNjgxMjE5Mjc2LCJpYXQiOjE2ODEyMTc0NzZ9.b78pV3miSns-ZTMqPRafzfZl8Z12L5Fu_yMBCdj1wNk"
}
```

The value of the result above is a JWT. When decoded you will find it to contain token claims such as username, roles and more. One important token claim restricts the lifetime of the token with a default **validity of 30 minutes.**

You can find the Swagger-generated page for this endpoint in the following [link](/protect-capital/v3.44/reference/authentication/authenticate).