Memos unofficial
POST/api/v1/auth/signin

Sign in with credentials

Authenticates a user with password credentials or an SSO provider. Supply the relevant credential object; password sign-in requires username and password, while SSO sign-in requires idpName, code, and redirectUri. The response includes an access token and sets a refresh-token cookie.

  • IdempotentThe SDK sends Idempotency-Key, so a retried request is only applied once.

2 body fields

Sign-in credentials, supplied in the passwordCredentials or ssoCredentials object.

passwordCredentialsobjectoptional
Username and password authentication.
ssoCredentialsobjectoptional
SSO provider authentication.

2 status codes
200Returns the authenticated user's information, an access token, and the access token's expiration time. Store the access token in memory rather than local storage.
userobjectoptional
The authenticated user's information.
accessTokenstringoptional
The short-lived access token for API requests. Store in memory only, not in localStorage.
accessTokenExpiresAtstringoptional
When the access token expires. Client should call RefreshToken before this time.
defaultReturns a standard error object containing an error code, developer-facing message, and optional details.
codeintegeroptional
The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
messagestringoptional
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
detailsarray<object>optional
A list of messages that carry the error details. There is a common set of message types for APIs to use.

Error handling

passwordCredentials must include username and password when used. ssoCredentials must include idpName, code, and redirectUri when used; codeVerifier is also available for SSO credentials.