Rotate an opaque refresh token
Consumes the submitted token and returns a new access/refresh pair. Reuse revokes the whole token family.
application/json- body
refreshToken*stringOpaque refresh token
0 <= length <= 512Token rotated
*/*- response
accessToken?stringShort-lived bearer JWT
refreshToken?stringOne-time opaque refresh token
curl -X POST 'https://api.monetaryai.uz/api/v1/auth/refresh' \ -H 'Content-Type: application/json' \ -d '{ "refreshToken": "string"}'{ "accessToken": "string", "refreshToken": "string"}Request a company registration email link POST
Central host accepts valid email syntax with a routable mail domain for registration and returns 202. No account-existence/delivery disclosure; links point to configured /magic?token=... origin. Legacy tenant-host behavior uses the tenant host, not a body tenant identifier. After the same email-domain checks, compatibility mode returns 204, including unknown, inactive, throttled or disabled-delivery requests. This does not confirm account existence or delivery. No token is returned; delivery is opt-in and links use a trusted configured origin.
Register an email-verified company owner POST
Central host only. Single-use acknowledged email token, matching email and confirmed password. Company name/STIR optional; creates an isolated onboarding workspace and ADMIN membership atomically. Existing identities cannot be overwritten. Backend returns bearer tokens; browser BFF stores HttpOnly cookies.