OAuth Authentication

Call OAuth provider API

Changed on

Make an authenticated request to an OAuth provider's API on behalf of the user. The user's stored access token is automatically used and refreshed if needed.

The request is always sent to the provider's fixed API base URL joined with the caller-supplied endpoint. endpoint must be a relative path beginning with / (optionally with a query string); it cannot change the target host. Absolute URLs, protocol-relative //host values, or userinfo (@host) are rejected with 400 so the request can never be redirected to another host.

Examples of endpoint:

  • Google userinfo: /oauth2/v1/userinfo
  • GitHub repositories: /user/repos
  • Microsoft Graph profile: /me

The response wraps the provider's raw JSON value with request metadata. An empty provider body is represented as data: null; the envelope preserves the provider's HTTP status in status_code, including errors. Provider response bodies are limited to 8 MiB after decompression. Transport failures, invalid JSON (including invalid UTF-8), and oversized bodies return 502. Provider redirects to another origin are blocked and return 400.

post/auth/oauth/{provider}/call-api

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/auth/oauth/{provider}/call-api
  • Auth: HTTP bearer

Path parameters

provider'google' | 'github' | 'microsoft' | 'apple' required

Request body

endpointstring required

Relative path on the provider's API, beginning with /. It is joined with the provider's fixed base URL; it must not contain a scheme, host, userinfo, or a leading //.

method'GET' | 'POST'

HTTP method to use

bodyobject

Request body for POST requests

Example request

{
  "endpoint": "/user/repos"
}

Response

Provider API response

provider'google' | 'github' | 'microsoft' | 'apple' required
endpointstring required
status_codeinteger required
dataunknown required

Changes

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the non-success response with the status

    • ○

      added the non-success response with the status