# Finish "Continue with Google" (Google redirects here)

`GET /v1/console/auth/google/callback` (operation id `completeGoogleSignIn`)

Google sends the browser here. The answer is always a 302 to the console and always clears the
`__Host-dex_google` cookie. The gateway checks `state` against the cookie, exchanges `code` at Google's token
endpoint with the PKCE verifier, and verifies the returned ID token (RS256 with Google's published keys,
issuer, audience = the web client id, expiry, and the nonce from the cookie). Google must have verified the
email address. The address is then treated exactly like a signed-in email code: an existing account with that
address is signed in, otherwise a new account is created.

On success the gateway sets the session cookie (as `createSession`) and redirects to
`https://thinqit.ai<return_path>#signed-in=google&csrf=<csrf_token>`. The console reads the CSRF token from the
fragment and removes it from the address bar; the fragment never reaches a server.

On failure it redirects to `https://thinqit.ai<return_path>#sign-in-error=<code>` (`/console/` when the cookie
was missing or invalid). Codes: `google_cancelled` (the person cancelled at Google), `google_state` (the state
cookie is missing, older than 10 minutes, tampered with, or does not match `state`), `google_failed` (the code
exchange or the ID token check failed, or Google returned another error), `google_email_unverified`,
`google_unavailable` (Google sign-in is not configured, or the database is down), `account_suspended`.
Other query parameters Google adds (`scope`, `authuser`, `prompt`, `hd`) are ignored.

Authentication: None. This route is public.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `code` | query | string | no | The authorization code from Google. (at most 2,048 characters) |
| `state` | query | string | no | The state sent to Google by `startGoogleSignIn`. (at most 128 characters) |
| `error` | query | string | no | Google's error, for example `access_denied` when the person cancelled. (at most 256 characters) |

## Responses

### 302

Back to the console, signed in (`#signed-in=google&csrf=<csrf_token>`) or not (`#sign-in-error=<code>`).

### 500

An unexpected error. Any charge was refunded. Retry with the same idempotency key.
