Skip to main content
POST
Log in

Body

application/json
email
string<email>
required
password
string
required
client_public_key
string<byte>

The client's per-session X25519 public key, used to seal responses. Required when the control plane runs with CUSTOS_ENCRYPTION on.

Response

Token pair

access_token
string

Opaque; valid for 15 minutes.

refresh_token
string

Opaque; valid for 30 days and rotated on every use.

expires_in
integer

Access-token lifetime in seconds, currently 900. A relative duration, not a timestamp — clients should add it to their own clock rather than trusting the server's.

Example:

900