Log in and obtain JWT tokens
Authenticates with email/password and starts a session: an access token and a refresh token. remember_me picks the session’s limits for its whole life: signed out after 3 idle days and at most 14 days after sign-in, or 30 idle days and 90 at most when true (current defaults) — see the Authentication and sessions guide for the full client contract.
Request
This endpoint expects an object.
email
password
remember_me
"Keep me signed in". false or omitted: signed out after 3 idle days, and at most 14 days after sign-in. true: 30 idle days, 90 at most. These are current defaults and server configuration — read exp from the refresh token rather than hardcoding them.
Response
Login successful
tokens
email
Errors
401
Unauthorized Error