Create a session

Creates a Person session using email and password, or creates a contractor-invite Person session when sessionType is Invite and the one-time invite token is supplied as Authorization: Bearer <inviteToken>. Guest sessions and non-null accountScope are rejected with 422. Invalid credentials return 401; MFA requirements return 403 StepUpMfaRequired.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

Real-login session — requires credentials. sessionType is explicit on the wire (the oneOf discriminator), removing V1's foot-gun of inferring guest-ness from an empty subject.

string
enum
required
Allowed:
string
required
length ≤ 320
password
required
length between 1 and 1024
string

reCAPTCHA token supplied by the public sign-in UI.

string

reCAPTCHA version for captchaToken.

boolean

True when the client was forced through the visible captcha challenge.

accountScope
object

Request a session token bound to a specific Account. This shape is reserved for account-authorized session creation and currently returns 422 ValidationError when sent as a non-null object. Omit the field or send null for an unbound Person session.

Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json