---
title: "perform a login using an external authenticator"
method: POST
path: "/auth/external/principal/login"
tags: ["external", "experimental", "auth"]
---

# perform a login using an external authenticator

`POST /auth/external/principal/login`

## Request body

- ExternalLoginInformation
  - `token_expiration_duration` integer
  - `identityRequest` object, required

## Response `200`

successful external login

- AuthenticationToken
  - `token` string, required — a JWT token that could be used to authenticate requests
  - `token_expiration` integer — Unix Epoch in seconds

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Resource Not Found
- `429` — too many requests
- `default` — Internal Server Error

## Changes

- **2025-07-29** `27799ffec9a5` — 2 info
  - added the non-success response with the status `429`
  - removed the non-success response with the status `420`
- **2024-09-17** `3b10653a8013` — 2 info
  - added the non-success response with the status `420`
  - removed the non-success response with the status `429`

[Change history](https://skmtc.dev/treeverse/apis/lakefs-api/changes/auth/external/principal/login/post.md)

---

[API](https://skmtc.dev/treeverse/apis/lakefs-api.md) · [All operations](https://skmtc.dev/treeverse/apis/lakefs-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/treeverse/lakefs-api/revisions/4617f80bee61/schema)
