Auth

Google OAuth callback

Handles the redirect back from Google. On success it: 1. Returning credential (`provider, providerUserId` already linked) → issues `pid_access` and `pid_refresh` cookies and redirects (with `pid_code` when the login carried an allowlisted `returnTo`). 2. New credential → mints a single-use claim ticket, sets the `pid_claim` cookie, and redirects to `CLIENT_SUCCESS_URL?claim=1` for the PID picker. Nothing is created until `POST /auth/claim`. Both cookies are `HttpOnly; SameSite=Lax`. In production the `Secure` flag is set. Strategy/transport failures (stale code, exchange error) redirect to `CLIENT_SUCCESS_URL?error=oauth_failed` instead of an error page — the wallet shows an inline retry. Cause stays in server logs only. **Browser-navigation only.** Google redirects the browser here; do not call it directly via `fetch()`.

GET
/auth/google/callback

Handles the redirect back from Google. On success it:

  1. Returning credential (provider, providerUserId already linked) → issues pid_access and pid_refresh cookies and redirects (with pid_code when the login carried an allowlisted returnTo).
  2. New credential → mints a single-use claim ticket, sets the pid_claim cookie, and redirects to CLIENT_SUCCESS_URL?claim=1 for the PID picker. Nothing is created until POST /auth/claim.

Both cookies are HttpOnly; SameSite=Lax. In production the Secure flag is set.

Strategy/transport failures (stale code, exchange error) redirect to CLIENT_SUCCESS_URL?error=oauth_failed instead of an error page — the wallet shows an inline retry. Cause stays in server logs only.

Browser-navigation only. Google redirects the browser here; do not call it directly via fetch().

Response Body

application/json

curl -X GET "https://example.com/auth/google/callback"
Empty