Login
POST/auth/login
Log in with email and password, starting a new session.
Other sessions of the account are left as they are (several sessions per
user). With X-Scrift-Web-Session the refresh token is set as the
HttpOnly web session cookie and left out of the body; without it, the body
carries it (the pre-cookie contract, until it is retired).
A request from a page outside the CORS allow-list is refused with 403
cross_site_request_refused (login CSRF).
Errors: 401 invalid_credentials; 403 email_not_verified for an
unverified account with the right password (#228); 429 when a limit is
spent (#223); 503 rate_limit_unavailable when the budget cannot be read.
Rate limits (#223): 10/minute per client address (slowapi), and a
budget of password checks per email, whatever client sends them
(rate_limit.LOGIN_ATTEMPTS_PER_ACCOUNT), spent atomically before the
password is checked. It answers the same for an email no account has.
Both live in Valkey; the budget fails closed when Valkey is down (#268).
Request
Responses
- 200
- 422
Successful Response
Validation Error