ReferenceAuth
/api/v1/auth/oidc/start
A form post (application/x-www-form-urlencoded) the browser follows: intent is login, link (connect the signed-in account) or setup (finish an account through its setup link, passed as setup); next is the SPA path to return to. Answers 303 to the provider, or back to the SPA with ?oidc=failed.
curl -X POST "https://example.com/api/v1/auth/oidc/start"Empty
/api/v1/auth/oidc/callback GET
The redirect URI the provider sends the browser back to with code and state. Answers 303 into the SPA: signed in, connected, or with ?oidc=unlinked|taken|linked|failed.
/api/v1/auth/password GET
Public, like GET /api/v1/auth/oidc: the login page asks before anyone is signed in.