Login
POST/api/v1/auth/login
User login endpoint. Returns JWT access and refresh tokens, and sets HttpOnly cookies.
Rate limited: 60/min per IP, 15/min per email. The per-email limit was raised from 5/min to 15/min to reduce false lockouts from mobile retries on flaky networks, typos, and app restarts. IP limit remains the primary abuse deterrent.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 422
- 429
- 500
OK
Bad Request
Unauthorized
Forbidden
Not Found
Validation Error
Too Many Requests
Internal Server Error