All the major OAuth providers. One profile API.Explore the quickstart
Documentation navigation

Login result

Fetch the clean-callback result from your backend using the original session key, client credentials and callback. Pending reads do not consume the session. A succeeded result carries profile; a failed result carries error. Terminal results are consumed atomically once; expiry, replay and invalid sessions return 400. Verify the initiating browser cookie before calling. No automatic retries after ambiguous failure.

On this page
POSThttps://api.anyoauth.com/v1/login/result

Authentication: Client ID and secret in JSON; confidential backend only.

Request

Content type: application/json.

FieldTypeRequiredDescription and constraints
client_idstringYesminLength: 1; maxLength: 100
client_secretstringYesminLength: 1; maxLength: 200
session_keystringYespattern: ^[A-Za-z0-9_-]{43}$
redirect_uristringYesExact registered HTTPS URL or HTTP loopback; no credentials, query or fragment. maxLength: 2048; format: uri; x-validation: redirect
Illustrative JSON request
{
"client_id": "YOUR_CLIENT_ID",
"client_secret": "YOUR_CLIENT_SECRET",
"session_key": "sssssssssssssssssssssssssssssssssssssssssss",
"redirect_uri": "https://your-app.example/auth/callback"
}

SDK and HTTP examples

Login result
import { AnyOAuth } from "@anyoauth/node";

const client = new AnyOAuth({
clientId: process.env.ANYOAUTH_CLIENT_ID ?? "YOUR_CLIENT_ID",
clientSecret: process.env.ANYOAUTH_CLIENT_SECRET ?? "YOUR_CLIENT_SECRET",
baseUrl: process.env.ANYOAUTH_API_ORIGIN ?? "https://api.anyoauth.com",
});

const result = await client.loginResult({
sessionKey: process.env.ANYOAUTH_SESSION_KEY ?? "sssssssssssssssssssssssssssssssssssssssssss",
redirectUri: process.env.ANYOAUTH_REDIRECT_URI ?? "https://your-app.example/auth/callback"
});

@anyoauth/node on GitHubConfidential backend SDK

Sample input bindings are illustrative. In a callback handler, take code and transaction values from the validated request and initiating session. Client-only SDKs do not perform confidential exchange.

Response

Success status: 200.

FieldTypeRequiredDescription and constraints
status"pending" | "succeeded" | "failed"Yes
profileobjectNo
profile.subjectstringYes
profile.provider"google" | "github"Yes
profile.providerSubjectstringYes
profile.namestring | nullYes
profile.usernamestring | nullYes
profile.emailstring | nullYes
profile.emailVerifiedbooleanYes
profile.avatarUrlstring | nullYes
error"access_denied" | "invalid_provider_response" | "provider_unavailable"No
Illustrative JSON response
{
"status": "succeeded",
"profile": {
"subject": "usr_example",
"provider": "google",
"providerSubject": "provider-subject",
"name": null,
"username": null,
"email": null,
"emailVerified": false,
"avatarUrl": null
}
}

Errors

Application errors use the shared error model. Infrastructure may return non-JSON responses; SDKs expose structured transport/protocol errors. Do not automatically retry a one-time code exchange.

FieldTypeRequiredDescription and constraints
errorstringYes
messagestringNo
Illustrative error response
{
"error": "request_failed",
"message": "The request could not be completed."
}

Contract source

This page, its field tables and sample inputs derive from OpenAPI version 0.1.0. Download OpenAPI · Download JSON Schema · Request schema · Response schema