Andrew Fletcher published: 16 May 2022 (updated) 7 June 2022 1 minute read
For an introduction into setting up RESTful hal+json refer to the set-up documentation. Also see the Query - user screen.
Login a member
POST: {domain}/user/login?_format=hal_json
Content-type: application/hal_json
Accept: application/hal+json
{
"name": "username",
"pass": "password"
}
Example:
{
"name": "jacque",
"pass": "nOtmYp1ssWorD"
}
Example response
{
"current_user": {
"uid": "200",
"name": "jacque"
},
"csrf_token": "kHVeh_ZWh5mwzZxrZGwc0smH3M5vfNX5C6H6oFyEVik",
"logout_token": "VGvCWlByqwU4r5d_D45t4Kj1TShDaCdNrEZZ3qtuAUQ"
}
If you are using json rather than hal_json, then accordingly alter the above to match. For example
POST: {domain}/user/login?_format=json
Content-type: application/json
Accept: application/json
Logout a member
GET {domain}/user/logout?_format=json&token={token}
Content-type: text/html
Replace {token} with your logout_token when the respective user logged in... for example
{
"logout_token": "VGvCWlByqwU4r5d_D45t4Kj1TShDaCdNrEZZ3qtuAUQ"
}
As noted from the example above.
Retrieve a user's details
GET {domain}/user/{uid}?_format=hal_json
For more details regarding retrieving a user's details go to Query - user.
Recover / change a user's password
Have read through this article - How to recover or change or reset your password using REST.
Check if a user is logged in or not
To confirm a user is logged in use:
GET {domain}/user/login_status?_format=json
If the user is logged in the response will be
1
Otherwise, a non logged user will be
0
Related articles
Andrew Fletcher
•
04 Apr 2025
Managing .gitignore changes
When working with Git, the .gitignore file plays a critical role in controlling which files and folders are tracked by version control. Yet, many developers are unsure when changes to .gitignore take effect and how to manage files that are already being tracked. This uncertainty can lead to...
Andrew Fletcher
•
26 Mar 2025
How to fix the ‘Undefined function t’ error in Drupal 10 or 11 code
Upgrading to Drupal 10.4+ you might have noticed a warning in their code editor stating “Undefined function ‘t’”. While Drupal’s `t()` function remains valid in procedural code, some language analysis tools — such as Intelephense — do not automatically recognise Drupal’s global functions. This...
Andrew Fletcher
•
17 Mar 2025
Upgrading to PHP 8.4 challenges with Drupal contrib modules
The upgrade from PHP 8.3.14 to PHP 8.4.4 presents challenges for Drupal 10.4 websites, particularly when dealing with contributed modules. While Drupal core operates seamlessly, various contrib modules have not yet been updated to accommodate changes introduced in PHP 8.4.x. This has resulted in...