---
title: "Sign in with email OTP"
method: POST
path: "/signin/otp/email"
tags: ["authentication"]
---

# Sign in with email OTP

`POST /signin/otp/email`

Initiate email-based one-time password authentication. Sends an OTP to the specified email address.
If the user doesn't exist and `AUTH_DISABLE_AUTO_SIGNUP` is not set, a new account will be created with the provided options.
When `AUTH_DISABLE_AUTO_SIGNUP` is enabled, users must use the `/signup/otp/email` endpoint to register first.

## Request body

- SignInOTPEmailRequest
  - `email` string, email, required — A valid email
  - `options` SignUpOptions
    - `allowedRoles` string[]
    - `defaultRole` string
    - `displayName` string
    - `locale` string — A two or three characters locale
    - `metadata` object
    - `redirectTo` string, uri

## Response `200`

OTP sent to the user's email. To prevent account enumeration, this response is also returned without side effects when the email is not registered and `AUTH_DISABLE_AUTO_SIGNUP` is enabled.

- 'OK'

## Other responses

- `default` — An error occurred while processing the request

## Changes

- **2026-06-24** `0fc5fd589dbf` — 1 warning
  - added the new `otp-too-many-attempts` enum value to the `error` response property for the response status `default`
- **2026-04-20** `b39086c84b43` — 1 warning, 1 info
  - added the new `user-already-exists` enum value to the `error` response property for the response status `default`
  - removed the `email-already-in-use` enum value from the `error` response property for the response status `default`
- **2026-01-13** `7560a2934be4` — 1 info
  - the `options/locale` request property's maxLength was increased from `2` to `3`
- **2025-11-11** `484d9f1a422a` — 1 warning
  - added the new `provider-account-already-linked` enum value to the `error` response property for the response status `default`
- **2025-10-09** `2bb5c4e40463` — 1 breaking, 1 warning, 3 info
  - the `options/locale` request property's maxLength was decreased to `2`
  - added the new `email-already-in-use` enum value to the `error` response property for the response status `default`
  - removed the `otp-too-many-attempts` enum value from the `error` response property for the response status `default`
  - removed the `provider-account-already-linked` enum value from the `error` response property for the response status `default`
  - …1 more

[Change history](https://skmtc.dev/nhost/apis/nhost-authentication-api/changes/signin/otp/email/post.md)

---

[API](https://skmtc.dev/nhost/apis/nhost-authentication-api.md) · [All operations](https://skmtc.dev/nhost/apis/nhost-authentication-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/nhost/nhost-authentication-api/revisions/a5c0d88b55c4/schema)
