Skip to content

Sign in with a username and password

POST
/auth/login
curl --request POST \
--url https://example.com/api/v1/auth/login \
--header 'Content-Type: application/json' \
--data '{ "username": "example", "password": "example" }'

Starts a session and sets the session cookie. Unknown usernames and wrong passwords get the same response. Repeated failures lock the account for a while, and each client address is rate limited.

Media typeapplication/json
object
username
required
string
>= 1 characters <= 255 characters
password
required
string
>= 1 characters <= 1024 characters
Examplegenerated
{
"username": "example",
"password": "example"
}

Signed in.

Media typeapplication/json
object
id
required
string format: uuid
username
required
string
email
required
string
displayName
required
string
globalAdmin
required
boolean
passwordChangeRequired
required

While true, only GET /me, POST /me/password and POST /auth/logout work.

boolean
createdAt
required
string format: date-time
Examplegenerated
{
"id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"username": "example",
"email": "example",
"displayName": "example",
"globalAdmin": true,
"passwordChangeRequired": true,
"createdAt": "2026-04-15T12:00:00Z"
}
Set-Cookie
string

The session cookie.

The request is invalid.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}

Not signed in, or the credentials are invalid.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}

Too many attempts; retry later.

Media typeapplication/problem+json

An RFC 9457 problem with a machine-readable code.

object
type
required
string
title
required
string
status
required
integer
detail
string
code
required

Stable machine-readable error code.

string
Example
{
"type": "about:blank",
"title": "Conflict",
"status": 409,
"code": "conflict"
}
Retry-After
integer

Seconds to wait.