Oauth Login
GET
/auth/oauth/{provider_slug}/login
const url = 'https://example.com/auth/oauth/example/login';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/auth/oauth/example/loginRedirect user to the IdP authorization URL with PKCE parameters.
Phase 268 H-27: the redirect_uri is handed to the IdP, where an
attacker-controlled origin (via X-Forwarded-Host) would otherwise
enable auth-code theft. We force explicit-config resolution by
passing for_external_use=True; falling back to the request-origin
is refused.
Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ” provider_slug
required
Provider Slug
string
Responses
Section titled “ Responses ”Successful Response
Bad request — invalid query parameters or payload
Media type application/problem+json
Unauthorized — missing or invalid credentials
Media type application/problem+json
Forbidden — caller lacks access to this resource
Media type application/problem+json
Not found
Media type application/problem+json
Validation error
Media type application/problem+json
Too many requests — retry after the advertised interval
Media type application/problem+json
Headers
Section titled “Headers ” Retry-After
integer
Seconds until the request may be retried
Internal server error
Media type application/problem+json
Service unavailable — the database could not serve the request
Media type application/problem+json