Skip to content

Begin federated sign-in

POST
/v1/auth/oidc/start
curl --request POST \
--url http://localhost:8080/v1/auth/oidc/start \
--header 'Content-Type: application/json' \
--data '{ "redirectUri": "example" }'

Anonymous, rate-limited. Returns the identity provider’s authorization URL for the browser to follow, carrying a sealed state (nonce + redirect URI + 10-minute expiry under the install’s master key) so the round trip needs no server session. 422 when federation is disabled or not fully configured.

Media typeapplication/json
object
redirectUri

The SPA’s callback URL; must sit on app.public_url’s origin.

string
Examplegenerated
{
"redirectUri": "example"
}

OK

Media typeapplication/json
object
authorizationUrl
required
string
state
required
string
Examplegenerated
{
"authorizationUrl": "example",
"state": "example"
}