Authentication
Complete login checkpoint
Completes a two-factor login checkpoint using either a TOTP code or a recovery token.
POST
/auth/login/checkpointRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/login/checkpoint" \ -H "Content-Type: application/json" \ -d '{ "confirmation_token": "b6e22f85d63c4d9db9739f9ab0a27a48f51f7ad38ef8c12fd157c4c6f4b2e51d" }'{ "data": { "complete": true, "intended": "/", "user": { "uuid": "9a8b7c6d-5e4f-4321-9876-123456789abc", "username": "admin", "email": "[email protected]", "name_first": "Admin", "name_last": "User", "language": "en", "root_admin": true, "use_totp": false, "gravatar": true, "created_at": "2026-06-29T12:00:00+00:00", "updated_at": "2026-06-29T12:00:00+00:00", "identifier": "usr_1a2b3c4d" } }}Login POST
Authenticates a browser session. Returns a complete login payload, or a two-factor checkpoint token when the account requires a second factor.
Request password reset email POST
Sends a password reset email when the account exists. The response is intentionally the same when no matching account is found.