Accounts
Sign in with a password
POST
/api/auth/loginSets the session cookie. When two-factor or a passkey is set up, the answer is instead { mfaRequired: true, ticket, methods } (or { mfaEnrolRequired: true, ticket } when a workspace requires two-factor the person has not set up): finish with POST /api/auth/mfa.
#Authentication
Public
No credential. Public routes are rate limited per address.