Skip to content

Security and sign-in

Single sign-on callback

GET/sso/callback

The provider’s answer. The ID token is verified locally against the provider’s keys; later sign-ins match on (issuer, sub) only.

#Authentication

Public

No credential. Public routes are rate limited per address.

A browser redirect in the single sign-on flow. The state and nonce are bound to a short-lived cookie.