post/auth/origin-handoff/redeem

Redeem origin handoff

Return the encrypted client state stored by create origin handoff and delete it in the same step. A wrong nonce also consumes the handoff. On the official instance the request must come from a first-party web origin.

redeem_origin_handoff

Request body

application/json

json
{
  "type": "object",
  "properties": {
    "handoff_id": {
      "type": "string",
      "pattern": "^[A-Za-z0-9_-]{43}$",
      "description": "Identifier returned when the handoff was created"
    },
    "nonce": {
      "type": "string",
      "minLength": 16,
      "maxLength": 256,
      "pattern": "^[A-Za-z0-9_-]+$",
      "description": "Nonce whose SHA-256 digest was sent when the handoff was created"
    }
  },
  "required": [
    "handoff_id",
    "nonce"
  ]
}

Responses

200

Success

json
{
  "type": "object",
  "properties": {
    "payload": {
      "type": "string",
      "description": "Encrypted client state encoded as base64url"
    }
  },
  "required": [
    "payload"
  ],
  "additionalProperties": false
}
400

Bad Request - The request was malformed or contained invalid data

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
429

Too Many Requests - You are being rate limited

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    },
    "retry_after": {
      "type": "number",
      "description": "Seconds to wait before retrying"
    },
    "global": {
      "type": "boolean",
      "description": "Whether this is a global rate limit"
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}
500

Internal Server Error - An unexpected error occurred

json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "Machine-readable error code"
    },
    "message": {
      "type": "string",
      "description": "Human-readable error message"
    },
    "errors": {
      "description": "Field-specific validation errors",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "description": "Field path that failed validation"
          },
          "code": {
            "description": "Machine-readable validation error code",
            "type": "string"
          },
          "message": {
            "type": "string",
            "description": "Human-readable validation error message"
          }
        },
        "required": [
          "path",
          "message"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "code",
    "message"
  ],
  "additionalProperties": {}
}