# Mint a browser login code **POST /auth/app-login/code** Create a one-time code that lets a desktop app or a script running on the same machine obtain its own tokens for the current user. The code is bound to the given PKCE challenge and expires after 60 seconds. Bots and sessions waiting for a 2FA setup cannot mint codes. ## Servers - http://api.example.com: http://api.example.com () ## Authentication methods - Jwt authorization ## Parameters ### Body: application/json (object) - **code_challenge** (string) Base64url encoded SHA-256 of the PKCE code verifier, without padding (43 characters) ## Responses ### 201 One-time login code #### Body: application/json (object) - **code** (string) One-time login code ### 400 Malformed code challenge [Powered by Bump.sh](https://bump.sh)