If `otp` is stored for the user, the next login becomes a two-step flow: `/login` returns `OTP_REQUIRED`, then `/login/otp/verify` issues tokens.
Already have an account? Sign In