> ## Documentation Index
> Fetch the complete documentation index at: https://docs.causeloop.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Log in a staff employee

> No auth required to call. Verifies email/password against `employees` (rejecting inactive accounts) and, on success, creates an `employee_sessions` row and writes a `control.audit_log` row (`employee_login`). Sets the httpOnly `cl_admin_session` cookie (12-hour lifetime) and the readable `cl_csrf` double-submit cookie every subsequent mutating staff request must echo back in the `X-CSRF-Token` header. Rate-limited per client IP and per email; exceeding the limit returns 429 with a `Retry-After` header. Returns 401 on any invalid credential (does not distinguish unknown email from wrong password). Implemented in `services/api/auth_api.py` and `services/api/auth/employee_auth.py`.



## OpenAPI

````yaml /api-reference/openapi.json post /admin/login
openapi: 3.1.0
info:
  title: CL MVP Product API
  description: >-
    The Causeloop MVP Product API is a deliberately small, explicitly
    allowlisted HTTP surface: `services/api/product_app.py` enumerates every one
    of the 44 published (method, path) operations drawn from seven routers, and
    only those operations are mounted onto this app -- everything else defined
    in the underlying routers (and the entire legacy research surface in
    `services/api/main.py`) is not exposed here. Staff (employee) and
    tenant-user sessions are separate cookie-based principals with no shared
    session table; mutating requests are protected by a double-submit CSRF
    cookie/header pair. See `/api-reference/authentication` for session and CSRF
    details, and `/api-reference/errors-and-conventions` for shared error shapes
    and status-code conventions.
  version: 1.0.0
servers: []
security: []
tags:
  - name: Auth
    description: >-
      Staff (employee) and tenant-user session lifecycle: login/logout,
      current-identity reads, invitation acceptance, and the public pre-login
      workspace directory.
  - name: Staff Onboarding
    description: >-
      The Onboarding Portal surface used to create, provision, ingest data for,
      train, activate, and go-live a tenant. Every operation requires an
      authenticated employee session; mutations additionally require the
      `onboarding_admin` control role (`support_readonly` employees can read but
      not write).
  - name: Insights
    description: >-
      Tenant-facing reads of materialized insight collections (themes, severity,
      issues, fishbone, and related model outputs) produced by the training and
      materialization pipeline.
  - name: Members
    description: Read-only tenant member directory.
  - name: Sources
    description: Tenant-facing source-connector registration and file-upload ingest.
  - name: Remediation
    description: >-
      Tenant-scoped corrective action plans (CAPs), human-in-the-loop issue
      reviews, the tenant audit trail, and the branded Excel export.
  - name: Health & Observability
    description: >-
      Unauthenticated liveness/readiness probes and the employee-only Prometheus
      metrics scrape endpoint.
paths:
  /admin/login:
    post:
      tags:
        - Auth
      summary: Log in a staff employee
      description: >-
        No auth required to call. Verifies email/password against `employees`
        (rejecting inactive accounts) and, on success, creates an
        `employee_sessions` row and writes a `control.audit_log` row
        (`employee_login`). Sets the httpOnly `cl_admin_session` cookie (12-hour
        lifetime) and the readable `cl_csrf` double-submit cookie every
        subsequent mutating staff request must echo back in the `X-CSRF-Token`
        header. Rate-limited per client IP and per email; exceeding the limit
        returns 429 with a `Retry-After` header. Returns 401 on any invalid
        credential (does not distinguish unknown email from wrong password).
        Implemented in `services/api/auth_api.py` and
        `services/api/auth/employee_auth.py`.
      operationId: admin_login_admin_login_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/EmployeeLoginRequest'
        required: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EmployeeMeResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    EmployeeLoginRequest:
      properties:
        email:
          type: string
          title: Email
        password:
          type: string
          title: Password
      type: object
      required:
        - email
        - password
      title: EmployeeLoginRequest
    EmployeeMeResponse:
      properties:
        id:
          type: string
          format: uuid
          title: Id
        email:
          type: string
          title: Email
        full_name:
          type: string
          title: Full Name
        control_role:
          type: string
          title: Control Role
      type: object
      required:
        - id
        - email
        - full_name
        - control_role
      title: EmployeeMeResponse
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````