Oauth Callback
GET
/auth/oauth/{provider_slug}/callback
const url = 'https://example.com/auth/oauth/example/callback';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/auth/oauth/example/callbackHandle IdP callback: exchange code, find/create user, issue JWT, redirect to frontend.
The frontend redirect carries access tokens in the URL
fragment. Without explicit-config resolution, an attacker controlling
X-Forwarded-Host could steer the post-callback redirect to
attacker.com and capture the tokens. Force explicit-config resolution
by passing for_external_use=True.
Parameters
Section titled “ Parameters ”Path Parameters
Section titled “ Path Parameters ” provider_slug
required
Provider Slug
string
Responses
Section titled “ Responses ”Successful Response
Bad request — invalid query parameters or payload
Media type application/problem+json
Unauthorized — missing or invalid credentials
Media type application/problem+json
Forbidden — caller lacks access to this resource
Media type application/problem+json
Not found
Media type application/problem+json
Validation error
Media type application/problem+json
Too many requests — retry after the advertised interval
Media type application/problem+json
Headers
Section titled “ Headers ” Retry-After
integer
Seconds until the request may be retried
Internal server error
Media type application/problem+json
Service unavailable — the database could not serve the request
Media type application/problem+json