authentication

Retrieve OAuth2 provider tokens from callback

After successful OAuth2 authentication, retrieve the provider session containing access token, refresh token, and expiration information for the specified provider. To ensure the data isn't stale this endpoint must be called immediately after the OAuth callback to obtain the tokens. The session is cleared from the database during this call, so subsequent calls will fail without going through the sign-in flow again. It is the user's responsibility to store the session safely (e.g., in browser local storage).

get/signin/provider/{provider}/callback/tokens

Path parameters

provider'apple' | 'github' | 'google' | 'linkedin' | 'discord' | 'spotify' | 'twitch' | 'gitlab' | 'bitbucket' | 'workos' | 'azuread' | 'entraid' | 'strava' | 'facebook' | 'windowslive' | 'twitter' required

The name of the social provider

Response

Successfully retrieved provider session

accessTokenstring required

OAuth2 provider access token for API calls

expiresIninteger required

Number of seconds until the access token expires

expiresAtstring date-time required

Timestamp when the access token expires

refreshTokenstring nullable

OAuth2 provider refresh token for obtaining new access tokens (if provided by the provider)

Example response

{
  "accessToken": "ya29.a0AfH6SMBx...",
  "expiresIn": 3599,
  "expiresAt": "2024-12-31T23:59:59Z",
  "refreshToken": "1//0gK8..."
}

Changes

Changed in 5 of the 15 revisions of this API.132

    • added the new otp-too-many-attempts enum value to the error response property for the response status default

      response-property-enum-value-added

  • b39086c84b4311See the full diff
    • added the new user-already-exists enum value to the error response property for the response status default

      response-property-enum-value-added

    • removed the email-already-in-use enum value from the error response property for the response status default

      response-property-enum-value-removed

    • added the new provider-account-already-linked enum value to the error response property for the response status default

      response-property-enum-value-added

    • endpoint added

      endpoint-added

    • api path removed without deprecation

      api-path-removed-without-deprecation

    This revision also has 20 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog