Ga naar inhoud

Log in with the setup code

POST
/auth/setup-login
curl --request POST \
--url https://example.com/auth/setup-login \
--header 'Content-Type: application/json' \
--data '{ "code": "example" }'

Starts a session with the one-time setup code of a fresh installation. That session only reaches what installation needs, such as linking the identity provider. The code stops working once an administrator has logged in through the identity provider. At most 10 attempts per minute.

  • None
Media typeapplication/json
object
code
required

The one-time setup code of the installation; case, spaces and dashes do not matter.

string

Example generated

{
"code": "example"
}

Logged in; the session cookie is set.

Media typeapplication/json

Who is calling: a user of the identity provider, an API key, or the break-glass token.

object
subject
required

The subject at the identity provider, or the id of the API key.

string
name
required
string
email
string | null
roles
required

viewer, operator and/or admin.

Array<string>
auth
required

How the caller authenticated: oidc, api_key, token or setup.

string
scopes

What the credential may be used for: management, gateway, setup.

Array<string>
via

cli for a user working through bl (decisions #62); the audit log says so. The same person in the UI has None.

string | null

Example generated

{
"subject": "example",
"name": "example",
"email": "example",
"roles": [
"example"
],
"auth": "example",
"scopes": [
"example"
],
"via": "example"
}

Wrong code.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

Installation is complete.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

Too many attempts.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}