> ## Documentation Index
> Fetch the complete documentation index at: https://docs.datris.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on (OIDC) callback

> The redirect URI registered at the identity provider. Checks `state` against the `datris-oidc-tx` cookie, exchanges the code (client secret from Vault, PKCE verifier), validates the ID token, resolves the Datris user and sets the session cookie. Every outcome is a redirect: `/` on success, otherwise `/login?ssoError=<code>` with one of `sso_denied`, `sso_failed`, `sso_no_account`, `sso_unverified_email`, `sso_identity_changed`. Provider error text is logged on the server, never returned. Recorded in the audit log as `auth` / `login`.



## OpenAPI

````yaml /openapi.yaml get /api/v1/auth/oidc/callback
openapi: 3.0.3
info:
  title: Datris API
  description: >
    REST API for the Datris AI Data Platform. Ingest, validate, transform,
    store, and retrieve data.


    For AI agent integration, use the [MCP
    Server](https://docs.datris.ai/mcp-server) instead.
  version: 1.28.0
  contact:
    name: Datris
    url: https://datris.ai
  license:
    name: Apache 2.0
servers:
  - url: http://localhost:8080
    description: Local development
security:
  - ApiKeyAuth: []
paths:
  /api/v1/auth/oidc/callback:
    get:
      tags:
        - Auth
      summary: Single sign-on (OIDC) callback
      description: >-
        The redirect URI registered at the identity provider. Checks `state`
        against the `datris-oidc-tx` cookie, exchanges the code (client secret
        from Vault, PKCE verifier), validates the ID token, resolves the Datris
        user and sets the session cookie. Every outcome is a redirect: `/` on
        success, otherwise `/login?ssoError=<code>` with one of `sso_denied`,
        `sso_failed`, `sso_no_account`, `sso_unverified_email`,
        `sso_identity_changed`. Provider error text is logged on the server,
        never returned. Recorded in the audit log as `auth` / `login`.
      parameters:
        - name: code
          in: query
          required: false
          schema:
            type: string
        - name: state
          in: query
          required: false
          schema:
            type: string
        - name: error
          in: query
          required: false
          schema:
            type: string
        - name: error_description
          in: query
          required: false
          schema:
            type: string
      responses:
        '302':
          description: >-
            Redirect to `/` (signed in, session cookie set) or to
            `/login?ssoError=<code>`
        '404':
          description: Single sign-on is not enabled on this server
      security: []
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: Optional API key for authentication (enabled via application.yaml)

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.