# API without Cake, problem with passwords

**URL:** <https://discourse.cakephp.org/t/api-without-cake-problem-with-passwords/1519>\
**Category:** Need Help\
**Created:** [November 12, 2016, 11:46am UTC](https://discourse.cakephp.org/t/api-without-cake-problem-with-passwords/1519 "2016-11-12T11:46:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![clem917](https://avatars.discourse-cdn.com/v4/letter/c/bc79bd/32.png) [@clem917](https://discourse.cakephp.org/u/clem917)\
**Post date:** [November 12, 2016, 11:46am UTC](https://discourse.cakephp.org/t/api-without-cake-problem-with-passwords/1519/1 "2016-11-12T11:46:34Z")

</div>

Hi,

I’m building a website (with CakePHP) and I will develop a mobile app. So, I make an API (not with cakephp) and I have some problems with the password : how can I write a request to check a user’s email and password ? How are the passwords hashed with auth component ?

Thanks a lot 🙂

---

<div class="post-metadata">

**Author:** ![JohnWayne](https://avatars.discourse-cdn.com/v4/letter/j/a698b9/32.png) [@JohnWayne](https://discourse.cakephp.org/u/JohnWayne)\
**Post date:** [November 19, 2016, 11:05pm UTC](https://discourse.cakephp.org/t/api-without-cake-problem-with-passwords/1519/2 "2016-11-19T23:05:56Z")

</div>

My solution was during user sign in process he sends his user name and pass to API and after success log in I am saving token in session and you can access to your API until the session is valid
