Login
auth
Login
email + password → access_token, refresh_token, user, workspace.
In dev mode any non-empty password (or empty) is accepted for seeded users. On a real deployment this verifies argon2id hash (identity-architecture.md §3.7b).
POST
Login