POST/api/auth/sign-in/email

Sign in with email and password

Authenticates a user by validating the supplied email and password credentials. Use the seed admin credentials provided by your environment administrator; repeated sign-in failures are rate-limited. A successful response sets an HttpOnly session cookie in the browser.

  • IdempotentThe SDK sends Idempotency-Key, so a retried request is only applied once.

2 body fields

Email and password credentials for the account to sign in.

emailstringrequired
The account email address, in valid email format.
passwordstringrequired
The account password.

4 status codes
200Returns the signed-in user's `id`, `email`, and `name`, and sets the session cookie in the response.
userobjectoptional
401Returned when the email or password is invalid.
messagestringoptional
codestringoptional
429Returned when too many sign-in attempts have been made.
errorstringrequired
500Returned when an unexpected server error occurs.
errorstringrequired

Error handling

A 401 is returned when the email or password is invalid, and a 429 is returned after too many sign-in attempts. A 500 is returned for an unexpected server error; email and password are required, and email must use a valid email format.