# Start "Continue with Google" (web console)

`GET /v1/console/auth/google/start` (operation id `startGoogleSignIn`)

The browser navigates here (a top-level navigation, not a fetch). The gateway answers 302 to Google's
authorization endpoint with the web client id, `redirect_uri` set to
`https://api.thinqit.ai/v1/console/auth/google/callback`, `response_type=code`, `scope=openid email profile`,
a random `state` and `nonce`, a PKCE `code_challenge` (S256) and `prompt=select_account`. It sets the
`__Host-dex_google` cookie (10 minutes) that carries the state, the PKCE verifier, the nonce and the return
path, signed with HMAC-SHA256.

When Google sign-in is not configured, or this client network started more than 60 Google sign-ins in the last
hour, the 302 goes to the console page instead, with the fragment `#sign-in-error=google_unavailable` or
`#sign-in-error=rate_limited`. No cookie is set then.

Authentication: None. This route is public.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `return_path` | query | string | no | The console page to return to after sign-in. A missing or invalid value becomes `/console/`. (at most 100 characters; pattern ^/console/[a-z0-9/-]*$) |
| `attribution` | query | string | no | Where the visitor came from: base64url (no padding) of the UTF-8 JSON of an `Attribution` object. Kept in the signed state cookie and used only when the sign-in creates the account. An invalid or oversized value is ignored (the sign-in goes on without it), never an error.  (at most 2,048 characters; pattern ^[A-Za-z0-9_-]+$) |

## Responses

### 302

To Google's sign-in page, or back to the console with `#sign-in-error=<code>`.

### 500

An unexpected error. Any charge was refunded. Retry with the same idempotency key.
