Integration OAuth2 callback (popup)
Browser-side OAuth callback for an authorization server fixed by the manifest. Exchanges code + state for tokens, persists the connection, and returns an HTML page that closes the popup window. A response for a flow started with an authorization server chosen per connection is refused here: it must arrive at that server's own /callback/{tag}. When the response carries iss (RFC 9207) it must name the authorization server the request was sent to, and a response without it is refused from a server that advertises authorization_response_iss_parameter_supported.
/api/integrations/callbackCookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Query Parameters
Authorization code returned by the IdP
OAuth state parameter (UUID)
OAuth error code (if the IdP rejected the request)
RFC 9207 issuer identifier of the authorization server that issued the response. Compared with the issuer the request was sent to whenever present.
curl -X GET "https://your-instance/api/integrations/callback"