---
title: "POST /api/v1/auth/spiffe-auth/login"
method: POST
path: "/api/v1/auth/spiffe-auth/login"
tags: ["SPIFFE Auth"]
---

# POST /api/v1/auth/spiffe-auth/login

`POST /api/v1/auth/spiffe-auth/login`

Login with SPIFFE Auth (JWT-SVID) for machine identity

## Request body

- object
  - `identityId` string, required — The ID of the machine identity to login.
  - `jwt` string, required — The JWT-SVID token to authenticate with.
  - `organizationSlug` string — When set, this will scope the login session to the specified organization the machine identity has access to. If omitted, the session defaults to the organization where the machine identity was created in.

## Response `200`

Default Response

- object
  - `accessToken` string, required
  - `expiresIn` number, required
  - `accessTokenMaxTTL` number, required
  - `tokenType` 'Bearer', required

## Other responses

- `400` — Default Response
- `401` — Default Response
- `403` — Default Response
- `404` — Default Response
- `422` — Default Response
- `500` — Default Response

---

[API](https://skmtc.net/infisical/apis/infisical-api.md) · [All operations](https://skmtc.net/infisical/apis/infisical-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/infisical/infisical-api/versions/885aef3e6c11/schema)
