Pending PID claim, if any
Returns the pending post-auth claim from the `pid_claim` cookie (verified credential, no identity yet) for the claim picker UI.
Returns the pending post-auth claim from the pid_claim cookie
(verified credential, no identity yet) for the claim picker UI.
Response Body
application/json
application/json
curl -X GET "https://example.com/auth/claim/status"{ "pending": true, "email": "new@example.com", "displayName": "New User", "avatarUrl": null}API Reference
Every endpoint of the PeridotID API
Google OAuth callback GET
Handles the redirect back from Google. On success it: 1. Returning credential (`provider, providerUserId` already linked) → issues `pid_access` and `pid_refresh` cookies and redirects (with `pid_code` when the login carried an allowlisted `returnTo`). 2. New credential → mints a single-use claim ticket, sets the `pid_claim` cookie, and redirects to `CLIENT_SUCCESS_URL?claim=1` for the PID picker. Nothing is created until `POST /auth/claim`. Both cookies are `HttpOnly; SameSite=Lax`. In production the `Secure` flag is set. Strategy/transport failures (stale code, exchange error) redirect to `CLIENT_SUCCESS_URL?error=oauth_failed` instead of an error page — the wallet shows an inline retry. Cause stays in server logs only. **Browser-navigation only.** Google redirects the browser here; do not call it directly via `fetch()`.