API reference, Console auth
Start "Continue with Google" (web console)
GET/v1/console/auth/google/startoperation id startGoogleSignIn
The browser navigates here (a top-level navigation, not a fetch). The gateway answers 302 to Google's
authorization endpoint with the web client id, redirect_uri set to
https://api.thinqit.ai/v1/console/auth/google/callback, response_type=code, scope=openid email profile,
a random state and nonce, a PKCE code_challenge (S256) and prompt=select_account. It sets the
__Host-dex_google cookie (10 minutes) that carries the state, the PKCE verifier, the nonce and the return
path, signed with HMAC-SHA256.
When Google sign-in is not configured, or this client network started more than 60 Google sign-ins in the last
hour, the 302 goes to the console page instead, with the fragment #sign-in-error=google_unavailable or
#sign-in-error=rate_limited. No cookie is set then.
Authentication. None. This route is public.
Parameters
return_pathquery · string/console/.at most 100 characterspattern ^/console/[a-z0-9/-]*$
attributionquery · stringAttribution object. Kept in
the signed state cookie and used only when the sign-in creates the account. An invalid or oversized value
is ignored (the sign-in goes on without it), never an error.at most 2,048 characterspattern ^[A-Za-z0-9_-]+$
Responses
302To Google's sign-in page, or back to the console with #sign-in-error=<code>.
Headers: x-request-id, location, set-cookie
500An unexpected error. Any charge was refunded. Retry with the same idempotency key.
Headers: x-request-id, x-client-request-id
Error envelope. See Errors for every type and code.