Hosted connect dispatch (token)

Public entry the connect URL points at. Verifies the single-use session token, pins a page cookie, then 302-redirects to the provider OAuth screen (oauth2) or the hosted form (non-oauth, and oauth2 of an integration declaring connection variables, which the form collects before submitIntegrationConnect starts the OAuth flow). On failure returns an HTML error page. Authenticated by the signed token, not a session.

GET/api/integrations/connect/start

Authorization

better-auth.session_token<token>

Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.

In: cookie

Query Parameters

token*string

Connect-session capability token.

curl -X GET "https://your-instance/api/integrations/connect/start?token=string"
Empty
"string"
"string"
"string"
{
  "type": "https://docs.appstrate.dev/errors/rate-limited",
  "title": "Rate Limited",
  "status": 429,
  "detail": "Too many requests. Please try again shortly.",
  "code": "rate_limited",
  "request_id": "req_abc123",
  "retry_after": 30
}
"string"
"string"