ReferenceAuth
/api/v1/auth/oidc
Public: the login page asks before anyone is signed in. The flow itself runs through POST /api/v1/auth/oidc/start, a form post the browser follows to the provider.
curl -X GET "https://example.com/api/v1/auth/oidc"{ "$schema": "https://example.com/api/v1/schemas/ProviderInfo.json", "enabled": true, "name": "string"}/api/v1/auth/me/profile PATCH
Its own path rather than PATCH /api/v1/auth/me, which is the password change and demands the current password - a rename has nothing to do with it.
/api/v1/auth/oidc/callback GET
The redirect URI the provider sends the browser back to with code and state. Answers 303 into the SPA: signed in, connected, or with ?oidc=unlinked|taken|linked|failed.