ReferenceAuth
/api/v1/auth/oidc/callback
The redirect URI the provider sends the browser back to with code and state. Answers 303 into the SPA: signed in, connected, or with ?oidc=unlinked|taken|linked|failed.
curl -X GET "https://example.com/api/v1/auth/oidc/callback"Empty
/api/v1/auth/oidc GET
Public: the login page asks before anyone is signed in. The flow itself runs through POST /api/v1/auth/oidc/start, a form post the browser follows to the provider.
/api/v1/auth/oidc/start POST
A form post (application/x-www-form-urlencoded) the browser follows: intent is login, link (connect the signed-in account) or setup (finish an account through its setup link, passed as setup); next is the SPA path to return to. Answers 303 to the provider, or back to the SPA with ?oidc=failed.