Integration OAuth2 callback of an authorization server chosen per connection (popup)

The redirect URI registered with, and sent to, an authorization server chosen per connection (AFPS §7.3: an oauth2 auth whose issuer or source.remote.url is a URL template over connection variables). One per server — the RFC 9700 §4.4 mix-up defence — so the response must arrive at the tag of the server the request was sent to: a mismatch is refused, as is a response for a fixed server. Otherwise identical to integrationsOAuthCallback, including the RFC 9207 iss check.

GET/api/integrations/callback/{tag}

Authorization

better-auth.session_token<token>

Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.

In: cookie

Path Parameters

tag*string

The authorization server's tag: the first 22 characters of base64url(SHA-256(issuer)), the issuer of its validated RFC 8414 metadata.

Match^[A-Za-z0-9_-]{22}$

Query Parameters

code?string

Authorization code returned by the IdP

state?string

OAuth state parameter (UUID)

error?string

OAuth error code (if the IdP rejected the request)

iss?string

RFC 9207 issuer identifier of the authorization server that issued the response. Compared with the issuer the request was sent to whenever present.

curl -X GET "https://your-instance/api/integrations/callback/string"
Empty