User Center

Unified Account Center (UAC): a global user pool with multi-method sign-up/log-in, Token issuance and verification, and email/phone verification for two-step sign-up.

/api/user_center/

Service Description

The user center is a unified account system (UAC): all integrated projects share one global user pool, so an account registered under one project can also log in under others, with no need to build a separate account system per project.

Sessions are carried by Tokens, and each Token is bound to the project that issued it. Sign-up supports email or mobile number only and is a two-step flow: submit the credential to receive a code, and the account is created only after the code is verified, which effectively prevents bulk malicious registrations. Password recovery follows the same pattern, sending a code first and verifying before the password is changed, and a successful reset invalidates all of that user's Tokens.

Apart from the available sign-up / log-in methods endpoint and the email activation link (public GET), all endpoints require project signature authentication. Clients should query the methods endpoint first and render the form from the result rather than hard-coding the supported methods.

User Account System

Unified Account Pool (Token bound to the integration project) Signature Required

Everything except methods and the email activation link (GET) requires a project signature. Two-step email/phone registration: call register first (it only stores the intent and sends a code), then call verify/email or verify/phone to create the account. Forgot password: call password/send for a code, then password/reset to set a new password (which also invalidates all of that user's Tokens).

GET /api/user_center/users/methods Total calls: 3

Available Sign-up / Login Methods

Returns the sign-up/log-in methods enabled in the backend (public, no signature required).

  • Returns data={methods:[email,phone], username:false}; clients should call this endpoint first before rendering the form — username=false means username + password sign-up is disabled.
POST /api/user_center/users/register Total calls: 2

Sign Up

Sign up (email / phone only): submit an email or phone number plus a password to start two-step sign-up, which sends the code first.

Optional: for display only, not a sign-up credential

Provide email → first step of two-step sign-up; the email must then be verified

Provide phone → first step of two-step sign-up; the phone number must then be verified

  • Provide at least one of email / phone; for two-step sign-up data.need_verify=true, and the account is created only after verify/email or verify/phone passes.
  • Providing username only (i.e. username + password sign-up) is disabled and returns 30001 (business rule restriction).
POST /api/user_center/users/login/send Total calls: 1

Send Login Verification Code

First step of email/phone verification-code login: verifies the account is registered, then sends the code (60-second cooldown).

POST /api/user_center/users/login Total calls: 8

Log In

Log in: account/email/phone + password, or email/phone + verification code. On success, returns a Token bound to the project.

Account + password login: the account issued by the system

Email + password login, or email + code verification login

Phone + password login, or phone + code verification login

Required when code is omitted: one of account/email/phone plus a password

With code, it uses email/phone verification-code login (no password needed)

  • Password login accepts any one of three identifiers: account / email / phone (email and phone must be registered).
  • 5 consecutive failures for the same project + credential + IP locks it for 15 minutes (returns 20040).
POST /api/user_center/users/password/send Total calls: 0

Send Password Reset Code

Forgot-password step 1: verify that the email/phone is registered, then send the code (60-second cooldown).

  • Only accounts with a bound email/phone are supported; username-only accounts have no verification channel and cannot reset the password themselves.
POST /api/user_center/users/password/reset Total calls: 0

Reset Password

Forgot-password step 2: after the code is verified, set the new password.

8-64 characters, must include both letters and numbers

  • A successful reset invalidates all Tokens issued to that user (every signed-in device must log in again).
POST /api/user_center/users/verify Total calls: 0

Verify Token

Lets sub-projects confirm a user's identity by verifying the token's validity.

Required: the login Token the user holds under this project (returned by a successful login)

  • Returns data={valid, user_id, account, username} on success.
POST /api/user_center/users/logout Total calls: 0

Log Out

Delete this Token under the current project.

Required: the login Token the user holds under this project (returned by a successful login)

GET /api/user_center/users/info Total calls: 0

User Info

Look up user information by token.

Required: the login Token the user holds under this project (returned by a successful login)

POST /api/user_center/users/verify/email Total calls: 1

Email Two-Step Verification (Code)

Verifies the email code and, once passed, creates and issues the account.

POST /api/user_center/users/verify/email/resend Total calls: 0

Resend Verification Email

Resend the two-step sign-up verification email (60-second cooldown).

POST /api/user_center/users/verify/phone Total calls: 1

Phone Two-Step Verification

Verifies the phone code and, once passed, creates and issues the account.

POST /api/user_center/users/verify/phone/send Total calls: 0

Send Sign-up SMS

Send the SMS verification code for two-step sign-up (60-second cooldown).

XiaoYingAPI · Unified API Aggregation Service