Begin federated sign-in
POST
/v1/auth/oidc/start
const url = 'http://localhost:8080/v1/auth/oidc/start';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"redirectUri":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url http://localhost:8080/v1/auth/oidc/start \ --header 'Content-Type: application/json' \ --data '{ "redirectUri": "example" }'Anonymous, rate-limited. Returns the identity provider’s authorization URL for the browser to follow, carrying a sealed state (nonce + redirect URI + 10-minute expiry under the install’s master key) so the round trip needs no server session. 422 when federation is disabled or not fully configured.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
redirectUri
The SPA’s callback URL; must sit on app.public_url’s origin.
string
Examplegenerated
{ "redirectUri": "example"}Responses
Section titled “Responses”OK
Media typeapplication/json
object
authorizationUrl
required
string
state
required
string
Examplegenerated
{ "authorizationUrl": "example", "state": "example"}