Skip to main content
This is a form-based authentication endpoint. It uses Laravel session cookies, not API tokens. All subsequent authenticated requests rely on the session cookie returned by this endpoint.

Endpoint

Middleware: guest — only accessible when the user is not already authenticated. Authenticated users will be redirected away.

Request

Parameters

string
required
The user’s email address. Must be a valid email format.
string
required
The user’s password.
boolean
When true, extends the session lifetime so the user remains logged in across browser restarts. Defaults to false.

Response

This endpoint does not return a JSON body. It responds with HTTP redirects. On success, a Set-Cookie header is returned containing the encrypted Laravel session cookie. Include this cookie in all subsequent requests to maintain the authenticated session.

Rate Limiting

Failed login attempts are rate-limited per email address and IP address. After 5 consecutive failed attempts, further requests are blocked until the lockout period expires. The error message on the email field will indicate how many seconds remain.

Example

The -c cookies.txt flag saves the session cookie to a file for use in subsequent requests.

Validation Errors

When validation fails, the server redirects back to /login and flashes errors into the session. When calling this endpoint from a JavaScript client (with Accept: application/json), a 422 Unprocessable Entity response is returned instead:
If credentials are incorrect, the error is attached to the email field: