auth
2 endpoints.
GET
/api/auth/token-info Bearer tokenDescribe the presented access token
Example protected endpoint: echoes back the claims of the bearer token after it has been validated against the OIDC provider.
Responses
| Status | Description | Body |
|---|---|---|
| 200 | The validated access token. | TokenInfo |
| 400 | The Authorization header does not use the Bearer scheme. | ErrorResponse |
| 401 | The access token is missing or invalid. | ErrorResponse |
| 403 | The access token is missing a required scope. | ErrorResponse |
| 500 | The access token could not be validated. | ErrorResponse |
GET
/api/.well-known/oauth-protected-resource PublicDescribe this API as an OAuth 2.0 protected resource
OAuth 2.0 Protected Resource Metadata (RFC 9728). Public: it names the authorization servers — the enabled sign-in providers — whose access tokens this API accepts, so a client can discover where to obtain one from the API's URL alone, and names the deployment after its branding. Also served at the root, `/.well-known/oauth-protected-resource`, which is the URL every 401 challenge points at in its `resource_metadata` parameter.
Responses
| Status | Description | Body |
|---|---|---|
| 200 | The metadata document. | ProtectedResourceMetadata |
| 500 | The sign-in providers could not be read. | ErrorResponse |