Skip to content

Complete OpenID Connect sign-in in the browser

GET
/api/v1/auth/oidc/{provider}/callback
curl --request GET \
--url https://example.com/api/v1/auth/oidc/example/callback

A link or re-auth flow already runs in a signed-in browser whose session the flow names (and re-auth marks fresh), so it keeps that session instead of receiving a second one. Complete OpenID Connect sign-in in the browser

Completes the OpenID Connect sign-in in the browser. The request must contain a valid OpenID Connect callback. A signed-in User is not needed. It can return 429 if the request limit is reached. Route: /api/v1/auth/oidc/{provider}/callback. Inputs: provider, code, state, error. Do not automatically replay this operation after an uncertain result.

provider
required
string

Configured OIDC provider name, as listed by GET /auth/options

code
string

Authorization code from the IdP.

state
string

The state returned by the flow start.

error
string

Set by the IdP instead of code when the user or IdP refused.

Redirect to the web app; ?sso=failed marks a failure

Too many requests

Media typeapplication/json
object
code
required
string
message
required
string
Examplegenerated
{
"code": "example",
"message": "example"
}