local-auth

Sign In

Exchange email, password and (if enrolled) a TOTP code for a session.

When the user belongs to exactly one organisation the session is scoped to it; otherwise the client selects one with select-organization. Every attempt is audited in each organisation the account belongs to: self-hosted installs have no identity provider keeping a sign-in log.

post/api/v1/auth/local/sign-in

Headers

X-Request-IDstring nullable

Request body

emailstring required
passwordstring required
totp_codestring nullable

Response

Successful Response

access_tokenstring required
token_typestring
expires_atstring date-time required
must_change_passwordboolean required
totp_enabledboolean required

Changes

Changed in 2 of the 13 revisions of this API.2