Finish federated sign-in
POST
/v1/auth/oidc/callback
const url = 'http://localhost:8080/v1/auth/oidc/callback';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"code":"example","state":"example","redirectUri":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url http://localhost:8080/v1/auth/oidc/callback \ --header 'Content-Type: application/json' \ --data '{ "code": "example", "state": "example", "redirectUri": "example" }'Anonymous, rate-limited. Exchanges the IdP’s code (confidential client), validates the id_token against the IdP’s JWKS; issuer, audience, lifetime, and the nonce sealed into state; and maps the proven email to an existing, active Bookend user. No account is created on the fly. Returns the same access/refresh pair as password sign-in. 401 when the state, code or token do not verify, or no matching active user exists; 422 when federation is disabled.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
code
string
state
string
redirectUri
string
Examplegenerated
{ "code": "example", "state": "example", "redirectUri": "example"}Responses
Section titled “Responses”OK
Media typeapplication/json
Access token (15 min default) + rotating refresh token, returned in the body and held in memory by the SPA.
object
accessToken
required
string
accessExpiresAt
required
string format: date-time
refreshToken
required
string
refreshExpiresAt
required
string format: date-time
user
required
object
id
required
string format: uuid
email
required
string
displayName
required
string
roles
required
Array<string>
isActive
required
boolean
lastLoginAt
required
null | string format: date-time
totpEnrolled
required
boolean
Examplegenerated
{ "accessToken": "example", "accessExpiresAt": "2026-04-15T12:00:00Z", "refreshToken": "example", "refreshExpiresAt": "2026-04-15T12:00:00Z", "user": { "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "email": "example", "displayName": "example", "roles": [ "example" ], "isActive": true, "lastLoginAt": "2026-04-15T12:00:00Z", "totpEnrolled": true }}