Complete an OAuth/OIDC callback
const url = 'https://example.com/v1/auth/callback/example';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"code":"example","state":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/v1/auth/callback/example \ --header 'Content-Type: application/json' \ --data '{ "code": "example", "state": "example" }'Public — the caller has not yet obtained a session token. Verifies state, exchanges code for provider tokens via the deployment’s exchangeCode, fetches userinfo, and persists a session via SessionStoreBinding. Returns an opaque kgi_sk_* session token the caller uses on subsequent requests. The underlying provider access-token never leaves the server. When the provider config populated allowedRedirectUris, the stored redirect_uri is re-checked against the current allowlist — a mismatch (allowlist tightened between login and callback) returns 400 redirect-uri-mismatch.
Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Request Bodyrequired
Section titled “Request Bodyrequired”object
Examplegenerated
{ "code": "example", "state": "example"}Responses
Section titled “Responses”Session created.
object
Opaque framework-issued session token (kgi_sk_<sessionId>). Send as Authorization: Bearer <sessionToken> on subsequent requests. The underlying provider access-token never leaves the server.
Examplegenerated
{ "sessionToken": "example", "sessionId": "example", "expiresAt": "2026-04-15T12:00:00Z"}Malformed body or state unknown/expired/consumed.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Code exchange with the provider failed.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}