---
title: "session: sign in"
description: "nothing, or the tenant to sign in to to the way the browser was opened, then the caller as a view once the code came back; the refresh token goes to the keychain and never to the caller"
section: reference
address: /reference/session/sign_in
contract: 0476e35e6e275db5
---

# session: sign in

nothing, or the tenant to sign in to to the way the browser was opened, then the caller as a view once the code came back; the refresh token goes to the keychain and never to the caller

[figure: The caller sends SignInInput to /v1/session/sign_in. The platform returns a card whose body is Caller.]

<span class="op-method">POST</span><span class="op-path">/v1/session/sign_in</span>

From the local server's own. The call needs the user rung under a token with the read grant, and it is served by the installed app.

The route takes [SignInInput](/concepts/signininput) and returns a card whose body is [Caller](/concepts/caller).



## Request body
The request body is [SignInInput](/concepts/signininput).



| field | type | required | note |
|---|---|---|---|
| `tenant` | `id` | no |  |
| `token` | `text` | no | an access token the identity provider issued, checked six ways at the face; never logged |



## Response
The route returns a card whose body is [Caller](/concepts/caller). Every card ends with a foot that states the basis of each number, the scope of the call, and the time when the facts were true.

## Headers


| header | required | meaning |
|---|---|---|
| `Scale-Scope` | yes | the scope the call runs in: tenant/<id>, then /brand/<id>, then /strategy/<id> |
| `Scale-As-True-On` | no | the date the facts must have been true on; defaults to now |
| `Scale-As-Known-On` | no | the date the facts must have been known on; defaults to now |
| `Scale-Key` | no | for a change, the key made from the input; a repeat under the same key returns the unit held and writes nothing |



A caller needs the user rung and a token with the read grant. The desktop app serves this route.

## Example
The example sends the smallest body that SignInInput allows. The build validates it against the schema of SignInInput.

<details class="wire"><summary>Example</summary>





```sh
curl -X POST https://api.scaleintelligence.co/v1/session/sign_in \
  -H "Scale-Key: $SCALE_KEY" -H "Scale-Scope: tenant/<id>" \
  -H "content-type: application/json" \
  -d '{}'
```




```typescript
import { client } from "@scale/sdk";
const answer = await client.session.sign_in({});
// answer.body is a Caller. answer.foot holds the basis, the scope and the time.
```




```python
import requests
answer = requests.post("https://api.scaleintelligence.co/v1/session/sign_in",
    headers={"Scale-Key": KEY, "Scale-Scope": "tenant/<id>"},
    json={}).json()
```




```rust
let answer: Card = client.post("https://api.scaleintelligence.co/v1/session/sign_in")
    .header("Scale-Key", key).header("Scale-Scope", "tenant/<id>")
    .json(&SignInInput { /* the fields of the page */ }).send().await?.json().await?;
```




</details>

## MCP tool
The MCP tool `si.session.sign_in` takes the same input and returns the same card. The tool only reads data. An MCP host that renders cards draws this card from `ui://scale-intelligence/cards/Caller`. The [tool's page](/reference/tools/si-session-sign_in) describes it.
