StartSSOLogin
POST/v1/auth/sso/start
StartSSOLogin opens the browser-shaped corporate SSO flow. Login hands PKCE orchestration to the CLI, which owns the loopback redirect; a browser has nowhere to keep a verifier, so this mints the whole attempt server-side and signs the return URL into the state. Any replica can then complete the callback -- no shared store, no session affinity (the reason login state is stateless at all, fraser#5339).
Public of necessity: it runs before anyone is signed in.
Request
Responses
- 200
Success