---
title: "Login account"
method: POST
path: "/auth/login"
tags: ["Auth"]
---

# Login account

`POST /auth/login`

Authenticate with email and password. Returns authentication token if credentials are valid and MFA is not required. If MFA is enabled, returns a ticket for MFA verification.

## Request body

- LoginRequest
  - `email` string, required
  - `password` string, required
  - `invite_code` string, nullable — Guild invite code to join after login

## Response `200`

Success

- union
  - AuthTokenWithUserIdResponse
    - `token` string, required — Authentication token for API requests
    - `user_id` string, snowflake, required
    - `user` UserPartialResponse, required
      - `id` string, snowflake, required
      - `username` string, required — The username of the user, not unique across the platform
      - `discriminator` string, required — The four-digit discriminator tag of the user
      - `global_name` string, nullable, required — The display name of the user, if set
      - `avatar` string, nullable, required — The hash of the user avatar image
      - `avatar_color` integer, required
      - `bot` boolean — Whether the user is a bot account
      - `system` boolean — Whether the user is an official system user
      - `flags` integer, required — The public flags on the user account
      - `mention_flags` 0 | 1 | 2 — Reply mention preference
  - object
    - `mfa` true, required — Indicates MFA is required to complete authentication
    - `ticket` string, required — MFA ticket to use when completing MFA verification
    - `allowed_methods` string[], required — List of allowed MFA methods
    - `totp` boolean, required — Whether TOTP authenticator MFA is available
    - `webauthn` boolean, required — Whether WebAuthn security key MFA is available
    - `backup_codes` boolean, required — Whether the account has at least one unconsumed backup code

## Other responses

- `400` — Bad Request - The request was malformed or contained invalid data
- `429` — Too Many Requests - You are being rate limited
- `500` — Internal Server Error - An unexpected error occurred

## Changes

> 21 revisions in range; 2 not diffed.

- **2026-09-20** `5296f41cd55d` — 1 info
  - added the required property `anyOf[subschema #2]/backup_codes` to the response with the `200` status
- **2026-09-18** `dd0ad4ea1c88` — 3 breaking, 3 info
  - request property `invite_code` list-of-types was narrowed by removing types `null` from media type `application/json`
  - the response property `anyOf[#/components/schemas/AuthTokenWithUserIdResponse]/user/avatar` became nullable for the status `200`
  - the response property `anyOf[#/components/schemas/AuthTokenWithUserIdResponse]/user/global_name` became nullable for the status `200`
  - the request property `invite_code` became nullable
  - …2 more
- **2026-09-06** `a52a2cf49d9b` — 16 warning, 100 info
  - added the new `IP_BAN_DECLINED` enum value to the `code` response property for the response status `400`
  - added the new `IP_BAN_DECLINED` enum value to the `code` response property for the response status `500`
  - added the new `PHONE_COUNTRY_NOT_SUPPORTED` enum value to the `code` response property for the response status `400`
  - added the new `PHONE_COUNTRY_NOT_SUPPORTED` enum value to the `code` response property for the response status `500`
  - …112 more
  - …this revision’s changelog is incomplete
- …earlier changes not shown

[Full history](https://skmtc.dev/fluxer/apis/fluxer-api/changes/auth/login/post.md)

---

[API](https://skmtc.dev/fluxer/apis/fluxer-api.md) · [All operations](https://skmtc.dev/fluxer/apis/fluxer-api/llms.txt) · [OpenAPI document](https://skmtc.dev/fluxer/apis/fluxer-api/revisions/3d3fd6ec1785?raw)
