> ## Documentation Index
> Fetch the complete documentation index at: https://docs.validate.al/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign in

> Authenticates with email and password, returns a JWT.



## OpenAPI

````yaml /api-reference/openapi.yaml post /auth/login
openapi: 3.0.3
info:
  title: validate.al API
  description: >-
    Email validation, security scanning and account management, all at
    https://api.validate.al.
  version: '1.0'
servers:
  - url: https://api.validate.al/v1
security:
  - ApiKeyAuth: []
tags:
  - name: Email validation
  - name: Scanning
  - name: Account
  - name: Health
paths:
  /auth/login:
    post:
      tags:
        - Account
      summary: Sign in
      description: Authenticates with email and password, returns a JWT.
      operationId: signIn
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - email
                - password
              properties:
                email:
                  type: string
                  example: user@example.com
                password:
                  type: string
                  example: ••••••••
                totp_code:
                  type: string
                  description: Required when two-factor authentication is on.
      responses:
        '200':
          description: Authenticated.
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
                  api_key:
                    type: string
                  email:
                    type: string
        '401':
          description: Invalid email or password.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            The address isn't confirmed yet (`detail.code` is
            `email_not_verified`), or the account is deactivated.
      security: []
components:
  schemas:
    Error:
      description: Errors from scanning and account endpoints.
      type: object
      properties:
        detail:
          type: string
          description: Error message
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: Your validate.al API key, from the portal (Settings → API Key).

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.