---
title: "Local-account login form (authorization flow)"
method: GET
path: "/login"
tags: ["OAuth"]
---

# Local-account login form (authorization flow)

`GET /login`

Render the local-account login form for an in-flight ``/authorize`` request.

Verifies the ``ls`` signature/TTL/purpose **before** rendering — an
expired, forged, or wrong-purpose token never gets a form — re-checks the
D7 client gate (a client denied or deactivated while the user holds the
``ls`` must not be asked for a password), rejects an already-spent ``ls``,
and embeds ``ls`` plus a fresh single-use CSRF nonce bound to it.

## Query parameters

- `ls` string, required — Signed authorization-flow state (carry-through token)

## Response `200`

Successful Response

## Other responses

- `400` — Bad Request
- `404` — Local-account login is unavailable (`auth.local_login.enabled=false`, or an external IdP is configured — `auth.idp.enabled=true` — which always wins): the route answers the framework's plain route-not-found 404, so the gate state is unobservable.
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-07** `b02360e6c1e1` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/login/get.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
