Skip to main content
POST
Verify OAuth provider authorization

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

environmentId
string
required

ID of the environment

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

providerType
enum<string>
required

Type of external auth provider The 'turnkey' value is deprecated and will be removed in a future version.

Available options:
emailOnly,
magicLink,
apple,
bitbucket,
coinbasesocial,
discord,
epicgames,
facebook,
farcaster,
github,
gitlab,
google,
instagram,
linkedin,
microsoft,
twitch,
twitter,
blocto,
banxa,
coinbaseOnramp,
cryptoDotCom,
moonPay,
dynamic,
alchemy,
zerodev,
telegram,
turnkey,
coinbaseWaas,
sms,
spotify,
tiktok,
line,
steam,
shopify,
zksync,
kraken,
blockaid,
passkey,
okta,
sendgrid,
resend,
trmWalletScreening,
chainalysisAddressScreening

Body

application/json

OAuth temporary auth code

state
string
required

Temporary auth state generated by the SDK; native mobile apps may append _client-redirect:

Maximum string length: 1200
Pattern: ^[A-Za-z0-9_-]{1,64}(_client-redirect:[A-Za-z0-9_:/?&=%.@#!$'()*+,;~\[\]-]{0,1024})?$
Example:

"aB3cD9fG0hJkLmN0pQrStUvWxYz_12-"

code
string

Temporary auth code for oauth2 access

codeVerifier
string

Temporary auth code verifier for oauth2 access

captchaToken
string

Optional captcha token to verify that the user is not a bot

sessionPublicKey
string
Pattern: ^(?=\S)[\p{L}\p{N}a-zA-Z _.,:!?&%@\/+\-'|]+(?<=\S)$
Example:

"An example name"

ssoProviderId
string
Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

requestedScopes
enum<string>[]

Optional list of scopes to include in the elevated access token.

Minimum array length: 1

Valid scopes for an elevated access token

Available options:
business_account:link_wallet,
business_account:member:add,
business_account:member:remove,
business_account:member:role:update,
business_account:signer:add,
business_account:signer:remove,
business_account:transfer_ownership,
business_account:wallet:remove,
console:admin_action:review,
console:approval_workflow:update,
console:member:invite,
console:mfa:reset,
console:project:delete,
console:settings:update,
console:sso:update,
console:user:delete,
credential:link,
credential:update,
credential:unlink,
user:update,
user:delete,
wallet:export,
wallet:delete,
wallet:delegate,
wallet:sign,
wallet:restore
Example:

Response

Success

user
object
required
expiresAt
number
required

Format is a unix-based timestamp. When set, this will be the expiration timestamp on the JWT sent using either the jwt field or a response httpOnly cookie set by the server.

Example:

"1715620310"

mfaToken
string

Token used to continue multi-factor authentication flow

jwt
string

Encoded JWT token. This will only be returned when cookie-based authentication is disabled in favor of standard Auth header based authentication.

Example:

"jwt_value"

minifiedJwt
string

Encoded JWT token. This will only be returned when cookie-based authentication is disabled in favor of standard Auth header based authentication.

Example:

"jwt_value"

elevatedAccessToken
string

Encoded JWT token for elevated access. This will only be returned when requestedScopes are requested.

Example:

"jwt_value"

Last modified on July 24, 2026