auth

2 endpoints.

GET/api/auth/token-info Bearer token

Describe the presented access token

Example protected endpoint: echoes back the claims of the bearer token after it has been validated against the OIDC provider.

Responses

StatusDescriptionBody
200The validated access token.TokenInfo
400The Authorization header does not use the Bearer scheme.ErrorResponse
401The access token is missing or invalid.ErrorResponse
403The access token is missing a required scope.ErrorResponse
500The access token could not be validated.ErrorResponse
GET/api/.well-known/oauth-protected-resource Public

Describe this API as an OAuth 2.0 protected resource

OAuth 2.0 Protected Resource Metadata (RFC 9728). Public: it names the authorization servers — the enabled sign-in providers — whose access tokens this API accepts, so a client can discover where to obtain one from the API's URL alone, and names the deployment after its branding. Also served at the root, `/.well-known/oauth-protected-resource`, which is the URL every 401 challenge points at in its `resource_metadata` parameter.

Responses

StatusDescriptionBody
200The metadata document.ProtectedResourceMetadata
500The sign-in providers could not be read.ErrorResponse