/api/auth/login
Validates a Cloudflare Turnstile token, checks the user’s credentials, and returns a signed JWT on success.
Request body
string
required
Username of the account to authenticate.
string
required
Plain-text password. Compared against the bcrypt hash stored in the database.
string
required
Cloudflare Turnstile token obtained from the client-side widget. Verified against the Turnstile
/siteverify endpoint before any credential check.Response
boolean
required
true on a successful login.string
required
Signed JWT. Expires in 8 hours. The payload contains
id, idPerfil, and nombre.object
required
Error responses
Store the returned token in an
auth_token cookie with maxAge set to 8 hours (28800 seconds) to match the JWT expiry.Examples
Success response
200