---
title: "Changes to OAuth callback for identity providers that POST the authorization code as form fields (Apple form_post).\r\nExtra form fields such as Apple's first-auth `id_token` and `user` are ignored;\r\nweb login exchanges code via PKCE and does not treat a form id_token as proof."
method: POST
path: "/v1/external/{identityProviderId}/sso/oauth/callback"
---

# Changes to OAuth callback for identity providers that POST the authorization code as form fields (Apple form_post).
Extra form fields such as Apple's first-auth `id_token` and `user` are ignored;
web login exchanges code via PKCE and does not treat a form id_token as proof.

`POST /v1/external/{identityProviderId}/sso/oauth/callback`

> Every recorded change to this endpoint, newest first.

## Timeline

Changed in 1 of 15 revisions.

- **2026-09-03** `d9b4ae8b3380` — 1 info

## Changes

- **2026-09-03** `d9b4ae8b3380` — 1 info
  - endpoint added

---

[Operation](https://skmtc.dev/roblox/apis/roblox-api/docs/v1/external/:identityProviderId/sso/oauth/callback/post.md) · [API](https://skmtc.dev/roblox/apis/roblox-api.md) · [Page](https://skmtc.dev/roblox/apis/roblox-api/changes/v1/external/:identityProviderId/sso/oauth/callback/post)
