> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.finput.com.au/api/endpoints/authentication/login/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.finput.com.au/_mcp/server. # Log in and obtain JWT tokens POST https://api.finput.com.au/api/v1/auth/login Content-Type: application/json Authenticates with email/password and starts a session: an access token and a refresh token. `remember_me` picks the session's limits for its whole life: signed out after 3 idle days and at most 14 days after sign-in, or 30 idle days and 90 at most when true (current defaults) — see the Authentication and sessions guide for the full client contract. Reference: https://docs.finput.com.au/api/endpoints/authentication/login ## Request ### Body (application/json) This endpoint expects a LoginRequest. - `email` (string, required) - `password` (string, required) - `remember_me` (boolean, optional, default: false) — "Keep me signed in". `false` or omitted: signed out after 3 idle days, and at most 14 days after sign-in. `true`: 30 idle days, 90 at most. These are current defaults and server configuration — read `exp` from the refresh token rather than hardcoding them. ## Response ### 200 Login successful - `tokens` (LoginResponseTokens, optional) - `email` (string, optional) ## Errors ### 401 Unauthorized Error Login refused. `code` is `invalid_credentials` for an unknown email, a wrong password or a locked-out account, all with the same `detail`. Only when the password is right does it say why the account cannot log in: `email_not_verified` (open the verification email, or `POST /api/v1/auth/resend-verification`) or `account_deactivated` (an organisation admin must reactivate it). - `detail` (string, required) — A sentence to show the user. - `code` (enum, required) — Why login was refused. `email_not_verified` and `account_deactivated` are only given for a correct password. - Allowed values: `invalid_credentials`, `email_not_verified`, `account_deactivated` ## Types ### LoginResponseTokens - `access` (string, optional) — JWT access token - `refresh` (string, optional) — JWT refresh token ## Examples **Request** ```json { "email": "user@example.com", "password": "securePassword123" } ``` **Response** ```json { "tokens": { "access": "string", "refresh": "string" }, "email": "string" } ``` **SDK Code** ```python import requests url = "https://api.finput.com.au/api/v1/auth/login" payload = { "email": "user@example.com", "password": "securePassword123" } headers = {"Content-Type": "application/json"} response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api.finput.com.au/api/v1/auth/login'; const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"email":"user@example.com","password":"securePassword123"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.finput.com.au/api/v1/auth/login" payload := strings.NewReader("{\n \"email\": \"user@example.com\",\n \"password\": \"securePassword123\"\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api.finput.com.au/api/v1/auth/login") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Content-Type"] = 'application/json' request.body = "{\n \"email\": \"user@example.com\",\n \"password\": \"securePassword123\"\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.finput.com.au/api/v1/auth/login") .header("Content-Type", "application/json") .body("{\n \"email\": \"user@example.com\",\n \"password\": \"securePassword123\"\n}") .asString(); ``` ```php request('POST', 'https://api.finput.com.au/api/v1/auth/login', [ 'body' => '{ "email": "user@example.com", "password": "securePassword123" }', 'headers' => [ 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api.finput.com.au/api/v1/auth/login"); var request = new RestRequest(Method.POST); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"email\": \"user@example.com\",\n \"password\": \"securePassword123\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["Content-Type": "application/json"] let parameters = [ "email": "user@example.com", "password": "securePassword123" ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.finput.com.au/api/v1/auth/login")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```