Handle the OAuth provider callback via GET (query parameters). Redirects to the client application with a challenge token or error.
Documentation Index
Fetch the complete documentation index at: https://docs.prelude.so/llms.txt
Use this file to discover all available pages before exploring further.
The OAuth provider identifier
"google"
The authorization code from the OAuth provider
"4/0AX4XfWh..."
The state parameter for CSRF protection
"st_01jqebhswje1ka1z7ahr9rfsgt"
Error code from the OAuth provider
"access_denied"
Error description from the OAuth provider
"The user denied access"
Redirect to the client application's redirect_uri with one of:
challenge_token=<jwt> — login may be finalized via the Finalize login endpoint.challenge_token=<jwt>&status=otp_required — the OAuth provider has verify_email=true and the IdP returned an unverified email. The SDK sends an email OTP and the host app must collect the code via the OTP screen; the SDK finalizes the login automatically once the OTP is verified.error=<code>&error_description=<message> — provider error or Session-level rejection (e.g. email_already_in_use).