---
title: "tool si.session.sign_in"
description: "nothing, or the tenant to sign in to: the way the browser was opened, then the caller as a view once the code came back; the refresh token goes to the keychain and never to the caller."
section: reference
address: /reference/tools/si-session-sign_in
contract: 0476e35e6e275db5
---

# tool si.session.sign_in

nothing, or the tenant to sign in to: the way the browser was opened, then the caller as a view once the code came back; the refresh token goes to the keychain and never to the caller.

[figure: Over MCP, si.session.sign_in takes SignInInput and returns a card whose body is Caller.]

the way the browser was opened, then the caller as a view once the code came back; the refresh token goes to the keychain and never to the caller. The call needs the read grant at the user rung.



| | |
|---|---|
| input | [SignInInput](/concepts/signininput) |
| result | a card whose body is [Caller](/concepts/caller) |
| read-only | yes |
| destructive | no |
| card address | `ui://scale-intelligence/cards/Caller` |
| HTTP route | [`/v1/session/sign_in`](/reference/session/sign_in) |





| field | type | required | note |
|---|---|---|---|
| `tenant` | `id` | no |  |
| `token` | `text` | no | an access token the identity provider issued, checked six ways at the face; never logged |
