Security and sign-in
Start single sign-on
GET
/sso/start?workspace=<slug>, or the person’s work email. Redirects to the identity provider with PKCE, state and nonce.
#Authentication
Public
No credential. Public routes are rate limited per address.
A browser redirect in the single sign-on flow. The state and nonce are bound to a short-lived cookie.