Skip to main content
POST
User login

Headers

x-firebase-appcheck
string

Body

application/json
email
string<email>
required
password
string
required
Minimum string length: 8

Response

Default Response

access_token
string
required

JWT access token to be used as Bearer token in Authorization header

passkey
boolean
required

Whether the account has at least one registered passkey

refresh_token
string

Also set as an httpOnly cookie for web clients; mobile clients store and POST this back to /auth/refresh

Last modified on October 7, 2026