v0alpha2

Initialize Login Flow for APIs, Services, Apps, ...

This endpoint initiates a login flow for API clients that do not use a browser, such as mobile devices, smart TVs, and so on.

If a valid provided session cookie or session token is provided, a 400 Bad Request error will be returned unless the URL query parameter ?refresh=true is set.

To fetch an existing login flow call /self-service/login/flows?flow=<flow_id>.

You MUST NOT use this endpoint in client-side (Single Page Apps, ReactJS, AngularJS) nor server-side (Java Server Pages, NodeJS, PHP, Golang, ...) browser applications. Using this endpoint in these applications will make you vulnerable to a variety of CSRF attacks, including CSRF login attacks.

In the case of an error, the error.id of the JSON response body can be one of:

session_already_available: The user is already signed in. session_aal1_required: Multi-factor auth (e.g. 2fa) was requested but the user has no session yet. security_csrf_violation: Unable to fetch the flow because a CSRF violation occurred.

This endpoint MUST ONLY be used in scenarios such as native mobile apps (React Native, Objective C, Swift, Java, ...).

More information can be found at Ory Kratos User Login and User Registration Documentation.

get/self-service/login/api

Query parameters

refreshboolean

Refresh a login session

If set to true, this will refresh an existing login session by asking the user to sign in again. This will reset the authenticated_at time of the session.

aalstring

Request a Specific AuthenticationMethod Assurance Level

Use this parameter to upgrade an existing session's authenticator assurance level (AAL). This allows you to ask for multi-factor authentication. When an identity sign in using e.g. username+password, the AAL is 1. If you wish to "upgrade" the session's security by asking the user to perform TOTP / WebAuth/ ... you would set this to "aal2".

Headers

X-Session-Tokenstring

The Session Token of the Identity performing the settings flow.

Response

selfServiceLoginFlow

active'password' | 'totp' | 'oidc' | 'webauthn' | 'lookup_secret'

and so on.

created_atstring date-time

CreatedAt is a helper struct field for gobuffalo.pop.

expires_atstring date-time required

ExpiresAt is the time (UTC) when the flow expires. If the user still wishes to log in, a new flow has to be initiated.

idstring uuid4 required
issued_atstring date-time required

IssuedAt is the time (UTC) when the flow started.

refreshboolean

Refresh stores whether this login flow should enforce re-authentication.

request_urlstring required

RequestURL is the initial URL that was requested from Ory Kratos. It can be used to forward information contained in the URL's path or query for example.

requested_aal'aal0' | 'aal1' | 'aal2' | 'aal3'

The authenticator assurance level can be one of "aal1", "aal2", or "aal3". A higher number means that it is harder for an attacker to compromise the account.

Generally, "aal1" implies that one authentication factor was used while AAL2 implies that two factors (e.g. password + TOTP) have been used.

To learn more about these levels please head over to: https://www.ory.sh/kratos/docs/concepts/credentials

return_tostring

ReturnTo contains the requested return_to URL.

typestring required

The flow type can either be api or browser.

updated_atstring date-time

UpdatedAt is a helper struct field for gobuffalo.pop.

Example response

{
  "expires_at": "2000-01-23T04:56:07.000+00:00",
  "ui": {
    "nodes": [
      {
        "meta": {
          "label": {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          }
        },
        "messages": [
          {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          },
          {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          }
        ],
        "type": "type",
        "group": "group"
      },
      {
        "meta": {
          "label": {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          }
        },
        "messages": [
          {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          },
          {
            "context": "{}",
            "id": 0,
            "text": "text",
            "type": "type"
          }
        ],
        "type": "type",
        "group": "group"
      }
    ],
    "method": "method",
    "action": "action",
    "messages": [
      {
        "context": "{}",
        "id": 0,
        "text": "text",
        "type": "type"
      },
      {
        "context": "{}",
        "id": 0,
        "text": "text",
        "type": "type"
      }
    ]
  },
  "updated_at": "2000-01-23T04:56:07.000+00:00",
  "created_at": "2000-01-23T04:56:07.000+00:00",
  "refresh": true,
  "return_to": "return_to",
  "id": "id",
  "type": "type",
  "issued_at": "2000-01-23T04:56:07.000+00:00",
  "request_url": "request_url"
}

Changes