Skip to main content

StartSSOLogin

POST 

/v1/auth/sso/start

StartSSOLogin opens the browser-shaped corporate SSO flow. Login hands PKCE orchestration to the CLI, which owns the loopback redirect; a browser has nowhere to keep a verifier, so this mints the whole attempt server-side and signs the return URL into the state. Any replica can then complete the callback -- no shared store, no session affinity (the reason login state is stateless at all, fraser#5339).

Public of necessity: it runs before anyone is signed in.

Request​

Responses​

Success