v15

latestOpenAPI 3.0.0MIT Licenseraw.githubusercontent.com2026-08-016088119.5 KB
authentication

Sign in with email and password

Authenticate a user with their email and password. Returns a session object or MFA challenge if two-factor authentication is enabled.

post/signin/email-password

Request body

emailstring email required

User's email address

passwordstring required

User's password

Example request

{
  "email": "john.smith@nhost.io",
  "password": "Str0ngPassw#ord-94|%"
}

Response

Authentication successful. If MFA is enabled, a challenge will be returned instead of a session.

Example response

{
  "session": {
    "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
    "accessTokenExpiresIn": 900,
    "refreshTokenId": "2c35b6f3-c4b9-48e3-978a-d4d0f1d42e24",
    "refreshToken": "2c35b6f3-c4b9-48e3-978a-d4d0f1d42e24",
    "user": {
      "avatarUrl": "https://myapp.com/avatars/user123.jpg",
      "createdAt": "2023-01-15T12:34:56Z",
      "defaultRole": "user",
      "displayName": "John Smith",
      "email": "john.smith@nhost.io",
      "emailVerified": true,
      "id": "2c35b6f3-c4b9-48e3-978a-d4d0f1d42e24",
      "locale": "en",
      "metadata": {
        "firstName": "John",
        "lastName": "Smith"
      },
      "phoneNumber": "+12025550123",
      "roles": [
        "user",
        "customer"
      ]
    }
  },
  "mfa": {
    "ticket": "mfaTotp:abc123def456"
  }
}