Ga naar inhoud

Log in at the identity provider

GET
/auth/login
curl --request GET \
--url https://example.com/auth/login

Redirects the browser to the participant’s OpenID Connect provider (authorization code with PKCE), and sets a short-lived cookie that binds the login to this browser: /auth/callback only finishes a login the same browser started. With device, the login is for a bl login: afterwards the browser goes to the confirmation page /cli/confirm (see POST /api/v1/cli/consent), and gets no session.

  • None
return_to
string

Where the browser goes after the login: a path on this service.

device
string

Approve bl login with this user code.

To the identity provider, or back to /login with an error.

No identity provider is linked.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}