Panel login
The browser session, not the API. A key needs none of this: it is a separate credential that two-factor never gates.
Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.
POST /api/auth/login
Section titled “POST /api/auth/login”Sign in; totpRequired means the cookie is only half a login.
- Level: No key
- Notes: Not over MCP
- Input:
{username, password}
POST /api/auth/login/totp
Section titled “POST /api/auth/login/totp”Finish a half-login with a code or recovery code.
- Level: No key
- Notes: Not over MCP
- Input:
{code}
POST /api/auth/logout
Section titled “POST /api/auth/logout”End this session.
- Level: Full
- Notes: Not over MCP
POST /api/auth/forgot-password
Section titled “POST /api/auth/forgot-password”Email a reset link to the account’s confirmed address; answers the same either way.
- Level: No key
- Notes: Not over MCP
- Input:
{login} - Returns:
{ok: true}
POST /api/auth/reset-password
Section titled “POST /api/auth/reset-password”Set a new password with the token from a reset link; ends every session of the account.
- Level: No key
- Notes: Not over MCP
- Input:
{token, newPassword} - Returns:
{ok: true, username}
POST /api/auth/confirm-email
Section titled “POST /api/auth/confirm-email”Make a pending address the recovery email, with the token from its link.
- Level: No key
- Notes: Not over MCP
- Input:
{token} - Returns:
{username, email}
POST /api/auth/logout-all
Section titled “POST /api/auth/logout-all”End every session of the signed-in admin; keys and other admins are untouched.
- Level: Full
- Notes: Destructive · Not over MCP
GET /api/auth/me
Section titled “GET /api/auth/me”Who this request is: the admin behind a session, or null for a key.
- Level: Read only
- Notes: Not over MCP
- Returns:
{user, authVia}