# login `POST /api/auth/login` accepts email, password, and remember-me preference. Successful local login issues an HttpOnly session cookie plus a readable CSRF cookie. Accounts with two-factor authentication receive a short-lived pending token and must complete `POST /api/auth/2fa/challenge` before a session is issued. Login and challenge endpoints are rate-limited. The frontend route is `/login`; registration has its own `/register` route. Authentication errors are shown without exposing whether an unknown account exists.