Authorisation Endpoint
POST/v3/service/extension/oidc/:organisationId/auth
Starts the authorisation flow. Takes the same parameters as the GET request, in a form encoded body. Returns an HTML page where individuals can authenticate using their EUDI Wallet through QR code or deep link verification. After the individual presents the credentials, the page redirects the browser to redirect_uri with code and state. When the individual does not answer within 15 minutes, the page redirects with error=interaction_required. The endpoint accepts GET and POST.
Request
Path Parameters
The ID of the organisation
- application/x-www-form-urlencoded
Body
required
Possible values: [openid]
Default value: openid
The scope of the access request
Possible values: [code]
Default value: code
The type of response desired
The ID of the client
The URI to which the response will be sent. It must match one of the redirect URIs of the client exactly.
An opaque value used to maintain state between the request and the callback
A string value used to associate a client session with an ID token, and to mitigate replay attacks
Responses
- 200
- 302
- 400
- 404
- 500
Returns a web page. The page shows the QR code and the link that opens the EUDI Wallet. When client_id is unknown, or when redirect_uri does not match a redirect URI of the client, the page shows the error and no redirect takes place.
Response Headers
X-Frame-Options any
Blocks page from being rendered in HTML frame, iframe, embed, or object elements, regardless of the site attempting to do so.
- text/html
- Schema
Schema
string
The request is refused, or the verification cannot start. The provider redirects the browser to redirect_uri with the query parameters error, error_description and state.
Response Headers
Location string
The redirect URI with the error parameters.
Bad request. The provider answers with an empty body when the request holds response_mode. The answer has errorCode and errorDescription when the organisation is not found.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
Not found. The Passwordless Login extension has never been enabled for the organisation.
Response Headers
- application/json
- Schema
- Example (from schema)
- Example
Schema
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "string",
"error_description": "string"
}
{
"error": "not_found",
"error_description": "Not found"
}
Internal server error. The answer has errorCode and errorDescription when it cannot reach the provider.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
- Provider error
- API error
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "server_error",
"error_description": "Internal server error"
}