OAuth

Local-account login submit (authorization flow)

Authenticate the local account and rejoin the authorization flow.

Success never mints a JWT — it flows straight into code issuance (platform client) or the consent handle (registered third-party client), exactly where the IdP callback rejoins, and burns the single-use ls. Credential failures re-render the form with one generic message: lockout state, unknown email, and wrong password are indistinguishable (no user-enumeration response oracle), while the shared AuthService.authenticate core still increments the failed-login count and applies the lockout threshold. An account flagged must_change_password authenticates but is told to rotate via the UI first — the OAuth plane must not hand a fully-scoped token to a temporary-password principal the UI would have boxed into change-password-only.

post/login

Response

Successful Response

{"stackTrail":"paths:/login:post:responses:200:content:application/json:schema","oasType":"schema","type":"unknown"}

Changes

Changed in 1 of the 114 revisions of this API.1