Docs menu

API reference, Console auth

Finish "Continue with Google" (Google redirects here)

View as Markdown

GET/v1/console/auth/google/callbackoperation id completeGoogleSignIn

Google sends the browser here. The answer is always a 302 to the console and always clears the __Host-dex_google cookie. The gateway checks state against the cookie, exchanges code at Google's token endpoint with the PKCE verifier, and verifies the returned ID token (RS256 with Google's published keys, issuer, audience = the web client id, expiry, and the nonce from the cookie). Google must have verified the email address. The address is then treated exactly like a signed-in email code: an existing account with that address is signed in, otherwise a new account is created.

On success the gateway sets the session cookie (as createSession) and redirects to https://thinqit.ai<return_path>#signed-in=google&csrf=<csrf_token>. The console reads the CSRF token from the fragment and removes it from the address bar; the fragment never reaches a server.

On failure it redirects to https://thinqit.ai<return_path>#sign-in-error=<code> (/console/ when the cookie was missing or invalid). Codes: google_cancelled (the person cancelled at Google), google_state (the state cookie is missing, older than 10 minutes, tampered with, or does not match state), google_failed (the code exchange or the ID token check failed, or Google returned another error), google_email_unverified, google_unavailable (Google sign-in is not configured, or the database is down), account_suspended. Other query parameters Google adds (scope, authuser, prompt, hd) are ignored.

Authentication. None. This route is public.

Parameters

codequery · string
The authorization code from Google.
  • at most 2,048 characters
statequery · string
The state sent to Google by startGoogleSignIn.
  • at most 128 characters
errorquery · string
Google's error, for example access_denied when the person cancelled.
  • at most 256 characters

Responses

302Back to the console, signed in (#signed-in=google&csrf=<csrf_token>) or not (#sign-in-error=<code>).

Headers: x-request-id, location, set-cookie

500An unexpected error. Any charge was refunded. Retry with the same idempotency key.

Headers: x-request-id, x-client-request-id

Error envelope. See Errors for every type and code.