Security and sign-in
Single sign-on callback
GET
/sso/callbackThe provider’s answer. The ID token is verified locally against the provider’s keys; later sign-ins match on (issuer, sub) only.
#Authentication
Public
No credential. Public routes are rate limited per address.
A browser redirect in the single sign-on flow. The state and nonce are bound to a short-lived cookie.