post/auth/origin-handoff

Create origin handoff

Store encrypted client state for up to two minutes so another first-party web origin can redeem it once. The receiving origin must present the nonce whose SHA-256 digest is sent here.

create_origin_handoff

Request body

application/json

json
{
  "type": "object",
  "properties": {
    "nonce_hash": {
      "type": "string",
      "pattern": "^[0-9a-f]{64}$",
      "description": "Lowercase hex SHA-256 digest of the nonce the receiving origin holds"
    },
    "payload": {
      "type": "string",
      "minLength": 1,
      "maxLength": 8388608,
      "pattern": "^[A-Za-z0-9_-]+$",
      "description": "Encrypted client state encoded as base64url"
    }
  },
  "required": [
    "nonce_hash",
    "payload"
  ]
}

Responses

200

Success

json
{
  "type": "object",
  "properties": {
    "handoff_id": {
      "type": "string",
      "description": "Single-use identifier the receiving origin redeems"
    }
  },
  "required": [
    "handoff_id"
  ],
  "additionalProperties": false
}
400

Bad Request - The request was malformed or contained invalid data

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
401

Unauthorized - Authentication is required or the token is invalid

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
403

Forbidden - You do not have permission to perform this action

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
429

Too Many Requests - You are being rate limited

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    },
    "retry_after": {
      "type": "number",
      "description": "Seconds to wait before retrying"
    },
    "global": {
      "type": "boolean",
      "description": "Whether this is a global rate limit"
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
500

Internal Server Error - An unexpected error occurred

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}