OAuth Authentication

Start OAuth authorization

Changed on

Redirects user to OAuth provider for authorization. Handles CSRF protection with state parameter. Project is identified via the anon_key query parameter.

get/auth/oauth/{provider}/authorize

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/auth/oauth/{provider}/authorize
  • Auth: none declared

Path parameters

provider'google' | 'github' | 'microsoft' | 'apple' required

Query parameters

anon_keystring required

Project anon key (required - identifies the project)

redirect_urlstring

URL to redirect to after the OAuth flow (optional). Must exactly match an entry in the project's allowed_redirect_urls, including its query string, or be the project's own managed hosted-auth page URL.

client_statestring

Optional application nonce. It is stored with the server-generated provider state and echoed to redirect_url as state.

response_mode'code'

Set to code to receive a short-lived authorization code at redirect_url, then use POST /auth/oauth/exchange to obtain the session. redirect_url is required in this mode. When omitted, the established session-fragment response is retained for compatibility with existing clients.

Changes

    • ○

      added the new optional query request parameter client_state

    • ○

      added the new optional query request parameter response_mode