# Email a one-time sign-in code

`POST /v1/console/auth/email-code` (operation id `requestSignInCode`)

Always answers 202 for a well-formed address, whether or not an account exists, so the route cannot be used
to discover accounts. The first successful sign-in creates the account. At most 5 codes per address per hour:
the sixth answers 429 `email_codes_per_hour` with `retry-after` set to the seconds until the oldest code of the
hour stops counting (up to 3,600), not a capped 60.

Authentication: None. This route is public.

## Request body

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `email` | string | yes | (format email; at most 254 characters) |

## Responses

### 202

A code was sent if the address can receive one.

### 400

The request could not be read. Codes: `invalid_json` (not JSON, not UTF-8, or a `\u` escape that is half of a
surrogate pair, such as `"\ud800"` without its low half), `duplicate_key` (a JSON object
repeats a key; `param` is the JSON pointer of the repeated member, such as `/questions/q1/options/a`),
`unsupported_media_type` (not `application/json`) and `invalid_header` (a malformed `idempotency-key` or
`x-client-request-id`; `param` names the header).


### 422

The request is well-formed JSON but breaks a validation rule. `param` names the field as a dotted path.
Codes: `unknown_field`, `missing_field`, `invalid_type` (wrong JSON type), `invalid_value` (right type, value
out of range: an empty or over-long string, a state, `instructions`, `criteria` string or option description
of only whitespace, an empty `questions` or `options` object, an empty state object or array, a pattern or
allowed-value mismatch such as a label or level with outer whitespace, a state nested deeper than 32 levels, a
bad date or date range), `field_not_allowed` (`options` or `levels` on the wrong question type),
`invalid_question_id`, `too_many_questions`, `too_many_options`, `invalid_levels` (including two levels equal
after Unicode NFC normalisation and lower-casing), `invalid_min_confidence`, `duplicate_label` (two option
labels equal after Unicode NFC normalisation and lower-casing, such as `Billing` and `billing`),
`state_path_not_found`, `state_not_json` and, on the console, `top_up_limit_exceeded`.


### 429

`email_codes_per_hour`: this address was sent 5 sign-in codes in the last hour, or too many codes were asked
for from this network. `retry-after` is the real wait until a code can be sent again, up to 3,600 seconds.


### 500

An unexpected error. Any charge was refunded. Retry with the same idempotency key.

### 503

`maintenance`: the console's database, sign-in or payments are unavailable for a moment. Retry after
`retry-after`. Nothing was changed.


## Examples

Illustrative values. Examples show the shape of requests and responses; the numbers in them are not measured results.

Request: email

```json
{
  "email": "dev@example.nl"
}
```
