OIDC callback endpoint

GET /auth/oidc/callback

Handles the identity provider callback. Validates the CSRF state, exchanges the authorization code for tokens via PKCE, finds or creates a user, and redirects to the UI with a one-time code.

Query parameters

  • code string Required

    Authorization code

  • state string Required

    CSRF state

Responses

  • 302 application/json

    Redirect to UI with one-time code

GET /auth/oidc/callback
curl \
 --request GET 'https://agentengine.mongodb.com/auth/oidc/callback?code=string&state=string' \
 --header "Authorization: $API_KEY"
Response examples (302)
string