# Log in a patient

Operation ID: `patient.login`

Authenticate a patient with email/password against their tenant's Cognito user pool (Cognito `USER_PASSWORD_AUTH`) and return access/ID tokens. Requires `tenant_id` to resolve the correct pool. Rejects with 403 when the user's role does not include `patient`, the token's tenant does not match the requested `tenant_id`, or the email has not yet been verified — call `patient.resendVerificationCode` in that last case.

## Public method

`login`

Signature: `auth.login(request)`

Return type: `Promise<LoginResponse>`

## Authentication

Classification: **PUBLIC**

## Prerequisites

None documented.

## HTTP

`POST /auth/login`

## Path parameters

None.

## Query parameters

None.

## Body parameters

| Name | Type | Required | Format | Allowed values | Default | Nullable | Description |
|---|---|---:|---|---|---|---:|---|
| `body` | [`patient.LoginRequest`](../models/patient.LoginRequest.md) | No |  |  |  | No |  |

Request model: [`patient.LoginRequest`](../models/patient.LoginRequest.md)

## Request example

```json
{
  "email": "jordan.patient@yopmail.com",
  "password": "PasswordTest1234$",
  "tenant_id": "tenant-example-001"
}
```

## Success responses

| Status | Shape | Content type | Description |
|---|---|---|---|
| `200` | [`patient.LoginResponse`](../models/patient.LoginResponse.md) | application/json | Patient login tokens |

## Success response examples

### 200

```json
{
  "access_token": "string",
  "athena_patient_id": "string",
  "cognito_sub": "string",
  "expires_in": 0,
  "fhir_patient_id": "string",
  "id_token": "string",
  "openloop_patient_id": "string",
  "refresh_token": "string",
  "steadymd_patient_guid": "string",
  "telehealth_id": 0,
  "token_type": "Bearer"
}
```

## Common errors

| Status | Shape | Content type | Description |
|---|---|---|---|
| `400` | [`patient.ErrorResponse`](../models/patient.ErrorResponse.md) | application/json | Bad request — email, password, or tenant_id is missing |
| `401` | [`patient.ErrorResponse`](../models/patient.ErrorResponse.md) | application/json | Invalid credentials or Cognito authentication failure |
| `403` | [`patient.ErrorResponse`](../models/patient.ErrorResponse.md) | application/json | Tenant/role mismatch, or the email is not yet verified |

## Error examples

### 400 — Required login fields are missing

```json
{
  "error": "email, password and tenant_id are required"
}
```

### 401 — Incorrect email or password

```json
{
  "error": "Incorrect username or password."
}
```

### 403 — The account's email has not been verified

```json
{
  "error": "Email not verified. Request a new code via /auth/resend-verification-code."
}
```

### 403 — The account does not have the patient role

```json
{
  "error": "Access denied: patient role required"
}
```

### 403 — The token's tenant does not match the requested tenant_id

```json
{
  "error": "Tenant mismatch"
}
```

## NodeJS / TypeScript implementation

```ts
import { HCSDK } from "@healthcloudai/hc-sdk";
import type { LoginRequest } from "@healthcloudai/hc-sdk";
```

```ts
const request = {
  "email": "jordan.patient@yopmail.com",
  "password": "PasswordTest1234$",
  "tenant_id": "tenant-example-001"
};

const result = await auth.login(request);
```

## cURL

```bash
curl -X POST \
  -H 'Content-Type: application/json' \
  -d '{"email":"jordan.patient@yopmail.com","password":"PasswordTest1234$","tenant_id":"tenant-example-001"}' \
  'https://dev-api-patient.health.cloud/auth/login'
```

## Notes

None.

## Prepared Test Console scenario

- `auth.login.success`

## Real response

No approved real integration response is currently published. Unapproved candidates are never rendered as examples.
