> ## Documentation Index
> Fetch the complete documentation index at: https://readme.amana-dev.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Log in

> Sign in with email and password to get an access token and a refresh token. Call this first, then send the access token as a Bearer token on every authenticated request.

## Headers

<ParamField header="x-firebase-appcheck" type="string" />

## Body

Content type: `application/json`

<ParamField body="email" type="string<email>" required>
  User's email address.
</ParamField>

<ParamField body="password" type="string" required>
  User's password.

  Minimum length: `8`
</ParamField>

## Response

`200` Success.

<ResponseField name="access_token" type="string">
  JWT access token to be used as Bearer token in Authorization header
</ResponseField>

<ResponseField name="refresh_token" type="string">
  Also set as an httpOnly cookie for web clients; mobile clients store and POST this back to /auth/refresh
</ResponseField>

<ResponseField name="passkey" type="boolean">
  Whether the account has at least one registered passkey
</ResponseField>

## Possible Errors

| Error | Possible cause | What to do |
| - | - | - |
| 400 | Invalid or missing field | Check the request against the schema. |
| 401 | Email or password is incorrect | Check the credentials and try again. |
| 403 | IP not whitelisted, or account restricted | Confirm your IP is whitelisted; otherwise contact Amana. |
| 404 | The requested item doesn't exist | Check the ID or path parameter. |
| 429 / 5xx | Rate limit, or temporary issue on our side | Retry with backoff; contact support if it persists. |

<RequestExample>
  ```bash cURL theme={null}
  curl --request POST \
    --url 'https://gateway.amana.io/auth/login' \
    --header 'Content-Type: application/json' \
    --data '{
    "email": "jsmith@example.com",
    "password": "<string>"
  }'
  ```

  ```python Python theme={null}
  import requests

  url = "https://gateway.amana.io/auth/login"
  headers = {"Content-Type": "application/json"}
  payload = {
      "email": "jsmith@example.com",
      "password": "<string>"
  }

  response = requests.request("POST", url, json=payload, headers=headers)
  print(response.json())
  ```

  ```javascript JavaScript theme={null}
  const response = await fetch('https://gateway.amana.io/auth/login', {
    method: 'POST',
    headers: {"Content-Type": "application/json"},
    body: JSON.stringify({"email": "jsmith@example.com", "password": "<string>"}),
  });
  console.log(await response.json());
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  {
    "access_token": "<string>",
    "refresh_token": "<string>",
    "passkey": true
  }
  ```

  ```json 400 theme={null}
  {
    "error": "<string>",
    "message": "<string>"
  }
  ```

  ```json 401 theme={null}
  {
    "error": "<string>",
    "email": "<string>",
    "ok": true
  }
  ```

  ```json 403 theme={null}
  {
    "error": "<string>",
    "ok": true
  }
  ```

  ```json 404 theme={null}
  {
    "error": "<string>",
    "message": "<string>",
    "details": {}
  }
  ```

  ```json 429 theme={null}
  {
    "error": "<string>",
    "ok": true
  }
  ```

  ```json 500 theme={null}
  {
    "error": "<string>",
    "message": "<string>",
    "details": {}
  }
  ```
</ResponseExample>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.