v1
latestOpenAPI 3.0.3Apache 2.02026-07-173769114.2 KBInitialize Login Flow for API clients
This endpoint initiates a login flow for API clients such as mobile devices, smart TVs, and so on.
If a valid provided session cookie or session token is provided, a 400 Bad Request error will be returned unless the URL query parameter ?refresh=true is set.
To fetch an existing login flow call /self-service/login/flows?flow=<flow_id>.
:::warning
You MUST NOT use this endpoint in client-side (Single Page Apps, ReactJS, AngularJS) nor server-side (Java Server Pages, NodeJS, PHP, Golang, ...) browser applications. Using this endpoint in these applications will make you vulnerable to a variety of CSRF attacks, including CSRF login attacks.
This endpoint MUST ONLY be used in scenarios such as native mobile apps (React Native, Objective C, Swift, Java, ...).
:::
More information can be found at Ory Kratos User Login and User Registration Documentation.
Query parameters
Refresh a login session
If set to true, this will refresh an existing login session by asking the user to sign in again. This will reset the authenticated_at time of the session.
Response
loginFlow