Skip to main content
POST
Sign Up

Overview

The sign-up endpoint creates a new user account in the Password Generator application. Upon successful registration, the endpoint returns JWT access and refresh tokens along with the user’s information.

Endpoint

Request Body

string
required
Unique username for the account. This field is required by Django’s AbstractUser model.
string
required
User’s email address. Must be unique in the system.
string
required
User’s password. Will be securely hashed using Django’s password hashing system.
string
User’s first name. Defaults to empty string if not provided.
string
User’s last name. Defaults to empty string if not provided.
string
User’s phone number. Maximum 10 characters. Can be null.

Response

string
JWT access token used for authenticating API requests. Short-lived token.
string
JWT refresh token used to obtain new access tokens when they expire.
object
User object containing the created user’s information.
integer
Unique identifier for the user.
string
User’s username.
string
User’s email address.
string
User’s first name.
string
User’s last name.
string
User’s phone number.
string
URL to user’s avatar image (if uploaded).

Example Request

cURL
Python
JavaScript

Example Response

201 Created

Error Responses

400 Bad Request - Missing Fields
400 Bad Request - Validation Error
500 Internal Server Error

Implementation Details

The sign-up endpoint is implemented in apps/users/views.py:49-79. Here’s how it works:
  1. Validation: The request data is validated against the UsersSerializer
  2. User Creation: If valid, a new user is created with the provided data
  3. Password Hashing: The password is securely hashed using user.set_password()
  4. Token Generation: JWT tokens are generated using RefreshToken.for_user(user)
  5. Response: Returns both tokens and the complete user object

Code Reference

From apps/users/views.py:49-79:

Notes

  • This endpoint does not require authentication (@permission_classes([AllowAny]))
  • The password is automatically hashed and never stored in plain text
  • Both access and refresh tokens are returned immediately upon successful registration
  • The user model extends Django’s AbstractUser (defined in apps/users/models.py:5)