Skip to main content
login() is a convenience wrapper around the unified token() exchange (grant_type: 'password') - same response shape as signup: { token, refresh_token, user: { id, email, role }, expires_at }.
K1005 (invalid credentials) and K1011 (email not verified, if the tenant requires it) are the errors to handle explicitly here - see Error codes.