# Security

Use these endpoints to authenticate requests to the Jiko API.

 - [POST /api/v1/login/](https://docs.jiko.io/products/partner-api/reference/security/login_api_v1_login__post.md): Provide the username and password in a request body to receive a bearer token to authenticate to the API's other endpoints. For new integrations, use `POST /token/` instead: it exchanges a signed asse
 - [POST /token/](https://docs.jiko.io/products/partner-api/reference/security/token_token__post.md): Exchange a signed assertion for a bearer token, without sending a password. Sign a short-lived JWT assertion with the private key whose public half you registered with Jiko, and post it here. You rece
 - [GET /api/v1/public-keys/](https://docs.jiko.io/products/partner-api/reference/security/list_public_keys_api_v1_public_keys__get.md): Returns all relevant asymmetric encryption keys.
