# How do I authenticate with the Casafari REST API?

> **Casafari is the AI agent-native real estate data intelligence platform.** The most complete property index in Europe: a deduplicated, cleaned property graph of residential and commercial property, for sale and for rent, in 16 countries. Every property is one record with its full price and market history. [How the property graph is built](/docs/property-graph).

Authenticate with the Casafari REST API by sending your `email` and `password` as JSON to `POST https://api.casafari.com/login`. It returns a JWT access token and a refresh token; the API doesn't use OAuth.

1. Send `{ "email": …, "password": … }` to [`POST /login`](https://platform.casafari.com/docs/rest/authentication/login). It responds `200` with `access_token` and `refresh_token`.
2. Include `Authorization: Bearer <access_token>` when you call any operation.
3. To get a new `access_token`, call [`GET /refresh-token`](https://platform.casafari.com/docs/rest/authentication/refresh-token) with the refresh token as the bearer.

A `401` from either endpoint means the credentials are wrong or the refresh token has expired, so log in again. A `422` from `/login` means the body is malformed, so send `email` and `password` as JSON. After you sign in, https://docs.api.casafari.com/ shows which operations your account may call.

See: [REST API](https://platform.casafari.com/docs/rest) and [REST authentication](https://platform.casafari.com/docs/rest/authentication).

## Where this is documented

- [Login](https://platform.casafari.com/docs/rest/authentication/login)
- [Refresh Token](https://platform.casafari.com/docs/rest/authentication/refresh-token)
- [REST API](https://platform.casafari.com/docs/rest)
- [Authentication](https://platform.casafari.com/docs/rest/authentication)

## Related questions

- [How does authentication work on Casafari MCP? Does it use OAuth scopes?](https://platform.casafari.com/docs/faq/how-authentication-works)
- [How does a client discover Casafari's authorization server?](https://platform.casafari.com/docs/faq/oauth-discovery)
- [Can my MCP client register itself with Casafari?](https://platform.casafari.com/docs/faq/dynamic-client-registration)
- [How does an agent sign in when no person is there to approve?](https://platform.casafari.com/docs/faq/unattended-agents)
- [What happens when my access token expires?](https://platform.casafari.com/docs/faq/token-expiry-refresh)

All questions: https://platform.casafari.com/docs/faq#rest-authentication
