Sign in
POST
/cognito/signin
Authenticate with email and password. Tokens are not returned in the body: the session is set as httpOnly cookies (access_token, id_token, refresh_token) that the browser sends on every later request. Scripts and server-to-server integrations should use an API key instead (see Authentication). When the risk engine flags repeated failures, a reCAPTCHA token must be sent as captchaToken. If Cognito asks for a further challenge, the body carries challengeRequired: true, challengeName and session and no cookies are set.
Request Body
application/json
JSON
{
"email": "user@example.com",
"password": "string",
"captchaToken": "string"
}
Responses
Authentication successful; session cookies set.
application/json
JSON
{
"message": "Signin successful",
"user": {
"id": "string",
"email": "string",
"name": "string",
"avatar": "string",
"role": "string",
"email_verified": true,
"created_at": "string",
"profile_slug": "string",
"deletion_scheduled_for": "string"
},
"expiresIn": 0
}