Log in with the setup code
const url = 'https://example.com/auth/setup-login';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"code":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/auth/setup-login \ --header 'Content-Type: application/json' \ --data '{ "code": "example" }'Starts a session with the one-time setup code of a fresh installation. That session only reaches what installation needs, such as linking the identity provider. The code stops working once an administrator has logged in through the identity provider. At most 10 attempts per minute.
Authorizations
Section titled “Authorizations”- None
Request Bodyrequired
Section titled “Request Bodyrequired”object
The one-time setup code of the installation; case, spaces and dashes do not matter.
Example generated
{ "code": "example"}Responses
Section titled “Responses”Logged in; the session cookie is set.
Who is calling: a user of the identity provider, an API key, or the break-glass token.
object
The subject at the identity provider, or the id of the API key.
viewer, operator and/or admin.
How the caller authenticated: oidc, api_key, token or setup.
What the credential may be used for: management, gateway, setup.
cli for a user working through bl (decisions #62); the audit log
says so. The same person in the UI has None.
Example generated
{ "subject": "example", "name": "example", "email": "example", "roles": [ "example" ], "auth": "example", "scopes": [ "example" ], "via": "example"}Wrong code.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}Installation is complete.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}Too many attempts.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}