# Login Details

Use these credentials **after** running `php artisan db:seed` (or `php artisan db:seed --class=UserSeeder`).

Emails are unique **per company**. Login uses **email + password** only:

- If that pair matches **one** account → sign in
- If it matches **more than one** account → contact your administrator
- Otherwise → incorrect credentials

---

## Super Admin (platform-level)

- **URL:** `POST /api/auth/login`
- **Email:** `superadmin@hrms.local`
- **Password:** `password`

Use for: managing the platform via the web Super Admin UI (`/superadmin/*`).

---

## Company Admin (tenant)

- **URL:** `POST /api/auth/login`
- **Email:** `admin@demo.local`
- **Password:** `password`

Use for: testing tenant features (employees, attendance, leaves, payroll) under **Demo Company**.

---

## Example: get a token

```bash
# Super Admin
curl -X POST http://localhost:8000/api/auth/login \
  -H "Content-Type: application/json" \
  -d "{\"email\":\"superadmin@hrms.local\",\"password\":\"password\"}"

# Company Admin
curl -X POST http://localhost:8000/api/auth/login \
  -H "Content-Type: application/json" \
  -d "{\"email\":\"admin@demo.local\",\"password\":\"password\"}"
```

Response includes `token` — use it as: `Authorization: Bearer <token>`.

---

**Important:** Change these passwords in production.
