> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# `POST /v1/control/sessions`: signs a reviewer in with a password.

> Every failure returns the same `401`. A login form that distinguishes
"no such account" from "wrong password" is a staff directory for anyone who
asks it politely.



## OpenAPI

````yaml /openapi.json post /v1/control/sessions
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers:
  - url: https://qa.esectra.com
    description: Esectra QA Documentation
security: []
paths:
  /v1/control/sessions:
    post:
      tags:
        - Control
      summary: '`POST /v1/control/sessions`: signs a reviewer in with a password.'
      description: >-
        Every failure returns the same `401`. A login form that distinguishes

        "no such account" from "wrong password" is a staff directory for anyone
        who

        asks it politely.
      operationId: login_handler
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LoginRequestBody'
        required: true
      responses:
        '201':
          description: A session cookie is set
        '401':
          description: Rejected; the same answer for every failure
        '429':
          description: Too many failed attempts; carries Retry-After
        '503':
          description: A backing store could not be reached
components:
  schemas:
    LoginRequestBody:
      type: object
      description: Credentials posted to the sign-in route.
      required:
        - username
        - password
      properties:
        method:
          $ref: '#/components/schemas/LoginMethod'
          description: Which credential store to check. Defaults to a local password.
        password:
          type: string
          description: The password, never logged and never echoed.
        username:
          type: string
          description: |-
            Email address, or the directory sign-in name when `method` is
            `directory`.
    LoginMethod:
      type: string
      description: Where a password is checked.
      enum:
        - password
        - directory

````