# Sign in with a password

Source: https://immiscible.fly.dev/docs/api/post-api-auth-login

`POST /api/auth/login`

Sets the session cookie. When two-factor or a passkey is set up, the answer is instead `{ mfaRequired: true, ticket, methods }` (or `{ mfaEnrolRequired: true, ticket }` when a workspace requires two-factor the person has not set up): finish with [`POST /api/auth/mfa`](https://immiscible.fly.dev/docs/api/post-api-auth-mfa.md).

## Authentication

Public. No credential. Public routes are rate limited per address.

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/api/auth/login" \
  -H "content-type: application/json" \
  -d '{
    "email": "sam@acme.example",
    "password": "a long passphrase"
  }'
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/api/auth/login', {
  method: 'POST',
  headers: {
    'content-type': 'application/json',
  },
  body: JSON.stringify({
    email: 'sam@acme.example',
    password: 'a long passphrase',
  }),
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import requests

res = requests.post(
    "https://immiscible.fly.dev/api/auth/login",
    headers={
        "content-type": "application/json",
    },
    json={
        "email": "sam@acme.example",
        "password": "a long passphrase",
    },
)
print(res.status_code, res.json())
```
