API reference, Console auth
Finish "Continue with Google" (Google redirects here)
GET/v1/console/auth/google/callbackoperation id completeGoogleSignIn
Google sends the browser here. The answer is always a 302 to the console and always clears the
__Host-dex_google cookie. The gateway checks state against the cookie, exchanges code at Google's token
endpoint with the PKCE verifier, and verifies the returned ID token (RS256 with Google's published keys,
issuer, audience = the web client id, expiry, and the nonce from the cookie). Google must have verified the
email address. The address is then treated exactly like a signed-in email code: an existing account with that
address is signed in, otherwise a new account is created.
On success the gateway sets the session cookie (as createSession) and redirects to
https://thinqit.ai<return_path>#signed-in=google&csrf=<csrf_token>. The console reads the CSRF token from the
fragment and removes it from the address bar; the fragment never reaches a server.
On failure it redirects to https://thinqit.ai<return_path>#sign-in-error=<code> (/console/ when the cookie
was missing or invalid). Codes: google_cancelled (the person cancelled at Google), google_state (the state
cookie is missing, older than 10 minutes, tampered with, or does not match state), google_failed (the code
exchange or the ID token check failed, or Google returned another error), google_email_unverified,
google_unavailable (Google sign-in is not configured, or the database is down), account_suspended.
Other query parameters Google adds (scope, authuser, prompt, hd) are ignored.
Authentication. None. This route is public.
Parameters
codequery · stringat most 2,048 characters
statequery · stringstartGoogleSignIn.at most 128 characters
errorquery · stringaccess_denied when the person cancelled.at most 256 characters
Responses
302Back to the console, signed in (#signed-in=google&csrf=<csrf_token>) or not (#sign-in-error=<code>).
Headers: x-request-id, location, set-cookie
500An unexpected error. Any charge was refunded. Retry with the same idempotency key.
Headers: x-request-id, x-client-request-id
Error envelope. See Errors for every type and code.