---
title: "Complete Login Flow with Username/Email Password Method"
method: POST
path: "/self-service/login/methods/password"
tags: ["public"]
---

# Complete Login Flow with Username/Email Password Method

`POST /self-service/login/methods/password`

Use this endpoint to complete a login flow by sending an identity's identifier and password. This endpoint
behaves differently for API and browser flows.

API flows expect `application/json` to be sent in the body and responds with
HTTP 200 and a application/json body with the session token on success;
HTTP 302 redirect to a fresh login flow if the original flow expired with the appropriate error messages set;
HTTP 400 on form validation errors.

Browser flows expect `application/x-www-form-urlencoded` to be sent in the body and responds with
a HTTP 302 redirect to the post/after login URL or the `return_to` value if it was set and if the login succeeded;
a HTTP 302 redirect to the login UI URL with the flow ID containing the validation errors otherwise.

More information can be found at [Ory Kratos User Login and User Registration Documentation](https://www.ory.sh/docs/next/kratos/self-service/flows/user-login-user-registration).

## Query parameters

- `flow` string, required

## Request body

- CompleteSelfServiceLoginFlowWithPasswordMethod
  - `csrf_token` string — Sending the anti-csrf token is only required for browser login flows.
  - `identifier` string — Identifier is the email or username of the user trying to log in.
  - `password` string — The user's password.

## Response `200`

loginViaApiResponse

- LoginViaApiResponse — The Response for Login Flows via API
  - `session` Session, required
    - `active` boolean
    - `authenticated_at` string, date-time, required
    - `expires_at` string, date-time, required
    - `id` string, uuid4, required
    - `identity` Identity, required
      - `id` string, uuid4, required
      - `recovery_addresses` RecoveryAddress[] — RecoveryAddresses contains all the addresses that can be used to recover an identity.
        - `id` string, uuid4, required
        - `value` string, required
        - `via` string, required
      - `schema_id` string, required — SchemaID is the ID of the JSON Schema to be used for validating the identity's traits.
      - `schema_url` string, required — SchemaURL is the URL of the endpoint where the identity's traits schema can be fetched from. format: url
      - `traits` Traits, required
      - `verifiable_addresses` VerifiableAddress[] — VerifiableAddresses contains all the addresses that can be verified by the user.
        - `id` string, uuid4, required
        - `status` string, required
        - `value` string, required
        - `verified` boolean, required
        - `verified_at` string, date-time
        - `via` string, required
    - `issued_at` string, date-time, required
  - `session_token` string, required — The Session Token A session token is equivalent to a session cookie, but it can be sent in the HTTP Authorization Header: Authorization: bearer ${session-token} The session token is only issued for API flows, not for Browser flows!

## Other responses

- `302` — Empty responses are sent when, for example, resources are deleted. The HTTP status code for empty responses is typically 201.
- `400` — loginFlow
- `500` — genericError

---

[API](https://skmtc.dev/ory/apis/ory-kratos-api.md) · [All operations](https://skmtc.dev/ory/apis/ory-kratos-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ory/ory-kratos-api/revisions/e77b8bae3f57/schema)
