OAuth

Local-account login form (authorization flow)

Render the local-account login form for an in-flight /authorize request.

Verifies the ls signature/TTL/purpose before rendering — an expired, forged, or wrong-purpose token never gets a form — re-checks the D7 client gate (a client denied or deactivated while the user holds the ls must not be asked for a password), rejects an already-spent ls, and embeds ls plus a fresh single-use CSRF nonce bound to it.

get/login

Query parameters

lsstring required

Signed authorization-flow state (carry-through token)

Signed authorization-flow state (carry-through token)

Response

Successful Response

Changes

Changed in 1 of the 114 revisions of this API.1