Skip to main content

Login

POST 

/auth/login

Log in with email and password, starting a new session.

Other sessions of the account are left as they are (several sessions per user). With X-Scrift-Web-Session the refresh token is set as the HttpOnly web session cookie and left out of the body; without it, the body carries it (the pre-cookie contract, until it is retired). A request from a page outside the CORS allow-list is refused with 403 cross_site_request_refused (login CSRF).

Errors: 401 invalid_credentials; 403 email_not_verified for an unverified account with the right password (#228); 429 when a limit is spent (#223); 503 rate_limit_unavailable when the budget cannot be read.

Rate limits (#223): 10/minute per client address (slowapi), and a budget of password checks per email, whatever client sends them (rate_limit.LOGIN_ATTEMPTS_PER_ACCOUNT), spent atomically before the password is checked. It answers the same for an email no account has. Both live in Valkey; the budget fails closed when Valkey is down (#268).

Request​

Responses​

Successful Response