---
title: "Sign-in step 1: verify credentials and start a step-2 session"
method: POST
path: "/identity/sign_in/step_1"
tags: ["identity", "signin"]
---

# Sign-in step 1: verify credentials and start a step-2 session

`POST /identity/sign_in/step_1`

## Request body

- IdentitySignInStep1Input
  - `email` string
  - `ip_address` string
  - `password` string
  - `required_group_id` string

## Response `200`

OK

- IdentitySignInStep1Output
  - `masked_phone_number` string
  - `session_token` string
  - `totp_secret` IdentityTOTPSecretOutput
    - `secret` string
    - `url` string
  - `twofa_method` string

## Other responses

- `default` — Error response.

## Changes

- **2026-09-01** `f2d9f80610d9` — 1 info
  - added the optional property `error/api_client_id` to the response with the `default` status
- **2026-08-06** `fe2041c5ba86` — 1 warning
  - changed the pattern of the request property `required_group_id` from `^grp_[0-9a-hjkmnp-tv-z]{26}$` to `^grp_[0-7][0-9a-hjkmnp-tv-z]{25}$`

[Change history](https://skmtc.dev/stablesea/apis/stable-sea-backend/changes/identity/sign_in/step_1/post.md)

---

[API](https://skmtc.dev/stablesea/apis/stable-sea-backend.md) · [All operations](https://skmtc.dev/stablesea/apis/stable-sea-backend/llms.txt) · [OpenAPI document](https://skmtc.dev/stablesea/apis/stable-sea-backend/revisions/352f74da5030?raw)
