---
id: post-oidc-auth
title: "Authorisation Endpoint"
description: "Starts the authorisation flow. Takes the same parameters as the GET request, in a form encoded body. Returns an HTML page where individuals can authenticate using their EUDI Wallet through QR code or deep link verification. After the individual presents the credentials, the page redirects the browser to `redirect_uri` with `code` and `state`. When the individual does not answer within 15 minutes, the page redirects with `error=interaction_required`. The endpoint accepts GET and POST."
sidebar_label: "Authorisation Endpoint"
hide_title: true
hide_table_of_contents: true
api: eJztWN1uG7sRfpUBgRwkwFrScXJuhKatE/uc6jQncWMHaWEY1mg50jLikhuSK1k1dNcn6aP1SYohd6XVT5ykQK/aK8tLcn6/+YbDByHJ505VQVkjhuIqoAseQkGAdSisUx55CabaLntwjXNKqx5LggodlhTIecD0+ZeLa3D0uSYfMlAGEKbWlUAmt5IkTKxc9eA9hdoZD2jgT9e/vYEKZwTLghyBMlItlKxRe8jRRCPIBJVjIKi9MjNWoxxcfDgfwUfUmgKEwtl6VsBf3gOrAetAElWglZnDgpya8nllTQ/OpoFctHSrCSpHnkzjdu5IskbUPosfonWOpHKUN3smzi49y7EwblfuaqfGsFShgDFbMQY0EsY+YKBxDz4WZPb1SksejA2Axi/JxcPKwI8/QalMHei4AUkFOWfdS2UCOczZtzsOu3Ikxz24LgjIyMoqEwDznKrgY2rYpMt3V9c9kYlt8sTw5mEPByxhdA52Gi2wboamQYLIhOIdFYZCZMJgSWIoujtGUmSitUYMg6spEz4vqEQxfBBhVfEJH5wyM7Fe36bN5MMrK1e8Y/9sbk0gE3gJq0o3yezfnyyXyxPG10ntdAMx3nSgy04+UR7YZ2crckGRT/ssL++blAkydSmGN8JWZJQUt5mQNMVaB5aVvmVHAhbltTHjsHvfFoNYs5e+ssbTXVL3ZbXsyK7S+OWYShbBGlvZIMnH0K0zkWtFJtwpeUzXY+lOB5PJW3B/m5QP70dcFstC5UUUtrFsqbSGCQGXWg9GAcraBygx5AVYs4lbq5Il+V2LgO4xD3rVY9NiYX3dpjMDtsLPNcECdc0cQpINLFGZgMpAlAMTCktqKrRJWSyWqBy1nmA+Z63GmvxbtEJa2FOK3ttcsT5sXfLkPfNrrGo0nIVg52SypN5CqYKa8RFHlcYVYAiYz71Yr7tFdtOAeR9lXRTspbMN4e16ve6gM1bG6WDAf3ad2tA2LGkSWSkxTeQnX9hlIseWhdvwRRYOBQbg0kl7OuzdUON4Y+cYlIfazI1dmoy5fBnXd3l2Q50JP7gDm13UdEh0a2Skz2iisduzIba3SmNOzJAd3gl0H/pFKPVRfnmkHmKDawS1drEtIga9IJSRgB/EX09+Zj4+eRdP+109dI9lpVnV+cXbvzEQdzW90jaf++Tk1NkSJsToc2QkOZLciaMhU1aRgWr+UjkhGWOcGBJIU8mdMANHM3RSM4U1VnvFuA2ByirEPmxBWvC2l1x5Pjg9hMx1p5wUk+GUSyFqZJHd3sztnhPq+QbSAMvZhZLkvq/78pbPNblV93qS+uU4a37cdczcbdQ7ad/N0BubLH0cAttUFSFUftjvJxj2moVebst+Syl/aNv4ArWSd02ofjiw8eXlxpUnpwMmziengwk9OR3URn2u6Ydo/UucDtT0k9dy/ukQI9d75LqNViqGbbSajL5IJPCF7vvJ70eiy0ZR5OvUteLv844tt9lXGvP29DbAfNWZketG+MVgsD4i/tGkvEKuhqoOW3/Z2/VhSaFsobuHxnRb8xvK5oJYxattoqpuDymslp5h2pByyTfDJK+59BXYovP19ta479N4K7l70+Ka4pqZ2tpIhu4WrSmBL74rgftJCSrEmF22nkezDmjuouHS6E5DFu8qMqNzaE/2jqf42yg0wZN7SsbTBDTJhPFe2XB1GxvuYjTGzDFjT25B7i4Vv2jBcicfR8uxukHPQ1DDW8n4CJoNsjYuiY0N4qg+8bbNmDgCu81iAskler+0DRG/sTNlgO4DmXhnYOgYWpCDCd9dyOBEk9xY2UXKITh++s7qtobeTeOk8N+EyTp72Mg7uxy1kb49Guhudr8Q6xEPSAY1pL3bzB0E/ujO/7hSVWj7mSNsbsJVpxi6uVhnPFS4dnYaisr68G50/vqsjiNWwBmPaGIvWPD0N76/BjJowjMm1ZJCYVsBccILhRiK/uJ5n51SOfU34OlbJfP+w+7ctu5jUplicGwwPKfSNiESmaid7jQ6SaU9wUr11MyhCT1lYz53BVw6K+s4sX5JzNckXAWc8QXkC8d9Wt435Ja9ymunwuqKQZ1o6KxSf6ZVhwQwfWiG3JSm7Zh7lt5E/t5Ownu3/ssRzGnVfbSIjw6MoTQINLAf78gZQ1KTBqIJA4Wm6p5kM+onG2EMT40NFAUEh0rHGFSY07MMqDfr7YkdQnPwdytbOw7HyZxWvx/H6ekVoSMXATZ8EJP438/WlcjT5q8frw99S+NsnE2gQu9b85Kkxma+aO4YAZsIRibhGCZlYnMH4LzFaUaZqW0pCfNISVSi4tz6uqqsC3/c5nOTEvXL9tMuELoY2vNmcwie/usf/3zGfRThaklS+QIkBgS6zws0szTG7NxTm1LaljPPsrUnD5709MTbBTlSMwMqviOFVdacZ3befV5CkGqmAmpYppcsVuatVhIqKyFQXhir7UzxU1Ckd845gqElaFqQZkDFN6BIIBOlVVhFIVgHW2K8p+e2rLRCk1NKWHTP0azW0R/fPNPVWjNypQrRzhKNSVSlVU7GR+Jtq6DCvCA47Q0OYr5cLnsYl3vWzfrNWd9/M3p98fbq4oTPrLctY5sHrh1p85rHj7a6mIJSvk4Hpy96z3s/8lkmtxJN156dl8qL5uFrH8KdXvf/Z87/nWfOhmXiAF9pVIYxFEH70DTIG7F43vQ8lceBpW2SIhPcJkUmhgcPnLFT3mai4F47vBEPDxP09MHp9Zo/xwlUDG9uM7FAF2s/dVPl4y1NDKeoPT2C0afvG0+fwaOvsUcdbLuZ4VYWe48YCpGJOTe7/dfa9e1m0I02pk2vkyUn1+kdqRXy9RdY7thJxFnMSefw9hll3b2vcK5EJibN+28ZJz/REZl1/xne8JPVvwGfNcCY
sidebar_class_name: "post api-method"
info_path: docs/extensions-api/igrant-io-api-documentation
custom_edit_url: null
---

> **Build this with an AI coding agent.** Install the iGrant.io Agent Skills, then ask your agent to build the integration:
>
> ```bash
> npx skills add L3-iGrant/skills
> ```


import ApiTabs from "@theme/ApiTabs";
import DiscriminatorTabs from "@theme/DiscriminatorTabs";
import MethodEndpoint from "@theme/ApiExplorer/MethodEndpoint";
import SecuritySchemes from "@theme/ApiExplorer/SecuritySchemes";
import MimeTabs from "@theme/MimeTabs";
import ParamsItem from "@theme/ParamsItem";
import ResponseSamples from "@theme/ResponseSamples";
import SchemaItem from "@theme/SchemaItem";
import SchemaTabs from "@theme/SchemaTabs";
import Markdown from "@theme/Markdown";
import OperationTabs from "@theme/OperationTabs";
import TabItem from "@theme/TabItem";

<h1 className={"openapi__heading"}>Authorisation Endpoint</h1>

<MethodEndpoint method={"post"} path={"/v3/service/extension/oidc/{organisationId}/auth"}></MethodEndpoint>



Starts the authorisation flow. Takes the same parameters as the GET request, in a form encoded body. Returns an HTML page where individuals can authenticate using their EUDI Wallet through QR code or deep link verification. After the individual presents the credentials, the page redirects the browser to `redirect_uri` with `code` and `state`. When the individual does not answer within 15 minutes, the page redirects with `error=interaction_required`. The endpoint accepts GET and POST.

## Request

<details style={{"marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collapsed={false} open={true}><summary style={{}}><h3 className={"openapi-markdown__details-summary-header-params"}>Path Parameters</h3></summary><div><ul><ParamsItem className={"paramsItem"} param={{"description":"The ID of the organisation","in":"path","name":"organisationId","required":true,"schema":{"type":"string"}}}></ParamsItem></ul></div></details><MimeTabs className={"openapi-tabs__mime"}><TabItem label={"application/x-www-form-urlencoded"} value={"application/x-www-form-urlencoded-schema"}><details style={{}} className={"openapi-markdown__details mime"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-mime"}><h3 className={"openapi-markdown__details-summary-header-body"}>Body</h3><strong className={"openapi-schema__required"}>required</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"scope"} required={true} schemaName={"string"} qualifierMessage={"**Possible values:** [`openid`]"} schema={{"type":"string","enum":["openid"],"default":"openid","description":"The scope of the access request"}}></SchemaItem><SchemaItem collapsible={false} name={"response_type"} required={true} schemaName={"string"} qualifierMessage={"**Possible values:** [`code`]"} schema={{"type":"string","enum":["code"],"default":"code","description":"The type of response desired"}}></SchemaItem><SchemaItem collapsible={false} name={"client_id"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The ID of the client"}}></SchemaItem><SchemaItem collapsible={false} name={"redirect_uri"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The URI to which the response will be sent. It must match one of the redirect URIs of the client exactly."}}></SchemaItem><SchemaItem collapsible={false} name={"state"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"An opaque value used to maintain state between the request and the callback"}}></SchemaItem><SchemaItem collapsible={false} name={"nonce"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"A string value used to associate a client session with an ID token, and to mitigate replay attacks"}}></SchemaItem></ul></details></TabItem></MimeTabs><div><div><ApiTabs label={undefined} id={undefined}><TabItem label={"200"} value={"200"}><div>

Returns a web page. The page shows the QR code and the link that opens the EUDI Wallet. When `client_id` is unknown, or when `redirect_uri` does not match a redirect URI of the client, the page shows the error and no redirect takes place.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}><li className={"schemaItem"}><summary style={{}}><strong>X-Frame-Options</strong><span style={{"opacity":"0.6"}}> any</span></summary><div><div style={{"marginTop":".5rem","marginBottom":".5rem"}}>

Blocks page from being rendered in HTML frame, iframe, embed, or object elements, regardless of the site attempting to do so.

</div></div></li></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"text/html"} value={"text/html"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><div style={{"marginTop":".5rem","marginBottom":".5rem","marginLeft":"1rem"}}>

string

</div></ul></details></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"302"} value={"302"}><div>

The request is refused, or the verification cannot start. The provider redirects the browser to `redirect_uri` with the query parameters `error`, `error_description` and `state`.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}><li className={"schemaItem"}><summary style={{}}><strong>Location</strong><span style={{"opacity":"0.6"}}> string</span></summary><div><div style={{"marginTop":".5rem","marginBottom":".5rem"}}>

The redirect URI with the error parameters.

</div></div></li></ul></details><div></div></TabItem><TabItem label={"400"} value={"400"}><div>

Bad request. The provider answers with an empty body when the request holds `response_mode`. The answer has `errorCode` and `errorDescription` when the organisation is not found.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"errorCode\": 400,\n  \"errorDescription\": \"Bad input parameter\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"404"} value={"404"}><div>

Not found. The Passwordless Login extension has never been enabled for the organisation.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><SchemaItem collapsible={false} name={"error"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The error code, for example `invalid_request`, `not_found` or `server_error`"}}></SchemaItem><SchemaItem collapsible={false} name={"error_description"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The reason for the error"}}></SchemaItem></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"error\": \"string\",\n  \"error_description\": \"string\"\n}"} language={"json"}></ResponseSamples></TabItem><TabItem label={"Example"} value={"Example"}><ResponseSamples responseExample={"{\n  \"error\": \"not_found\",\n  \"error_description\": \"Not found\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem><TabItem label={"500"} value={"500"}><div>

Internal server error. The answer has `errorCode` and `errorDescription` when it cannot reach the provider.

</div><details style={{"textAlign":"left","marginBottom":"1rem"}} className={"openapi-markdown__details"} data-collaposed={true} open={false}><summary style={{}}><strong>Response Headers</strong></summary><ul style={{"marginLeft":"1rem"}}></ul></details><div><MimeTabs className={"openapi-tabs__mime"} schemaType={"response"}><TabItem label={"application/json"} value={"application/json"}><SchemaTabs className={"openapi-tabs__schema"}><TabItem label={"Schema"} value={"Schema"}><details style={{}} className={"openapi-markdown__details response"} data-collapsed={false} open={true}><summary style={{}} className={"openapi-markdown__details-summary-response"}><strong>Schema</strong></summary><div style={{"textAlign":"left","marginLeft":"1rem"}}></div><ul style={{"marginLeft":"1rem"}}><div><span className={"badge badge--info"}>oneOf</span><SchemaTabs><TabItem label={"Provider error"} value={"0-item-properties"}><SchemaItem collapsible={false} name={"error"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The error code, for example `invalid_request`, `not_found` or `server_error`"}}></SchemaItem><SchemaItem collapsible={false} name={"error_description"} required={false} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","description":"The reason for the error"}}></SchemaItem></TabItem><TabItem label={"API error"} value={"1-item-properties"}><SchemaItem collapsible={false} name={"errorCode"} required={true} schemaName={"integer"} qualifierMessage={undefined} schema={{"type":"integer","example":400}}></SchemaItem><SchemaItem collapsible={false} name={"errorDescription"} required={true} schemaName={"string"} qualifierMessage={undefined} schema={{"type":"string","example":"Bad input parameter"}}></SchemaItem></TabItem></SchemaTabs></div></ul></details></TabItem><TabItem label={"Example (from schema)"} value={"Example (from schema)"}><ResponseSamples responseExample={"{\n  \"error\": \"server_error\",\n  \"error_description\": \"Internal server error\"\n}"} language={"json"}></ResponseSamples></TabItem></SchemaTabs></TabItem></MimeTabs></div></TabItem></ApiTabs></div></div>
      