Skip to main content
POST /api/auth/login Validates a Cloudflare Turnstile token, checks the user’s credentials, and returns a signed JWT on success.

Request body

string
required
Username of the account to authenticate.
string
required
Plain-text password. Compared against the bcrypt hash stored in the database.
string
required
Cloudflare Turnstile token obtained from the client-side widget. Verified against the Turnstile /siteverify endpoint before any credential check.

Response

boolean
required
true on a successful login.
string
required
Signed JWT. Expires in 8 hours. The payload contains id, idPerfil, and nombre.
object
required

Error responses

Store the returned token in an auth_token cookie with maxAge set to 8 hours (28800 seconds) to match the JWT expiry.

Examples

Success response

200