Skip to main content
POST
Start or continue a multi-step custom auth flow

Authorizations

X-Api-Key
string
header
required

Body

application/json

Request body for the /custom-auth/connect endpoint. The first call supplies the flow inputs; subsequent calls supply sessionId and callbackParams to resume after a redirect.

projectIdOrName
string
required

The Ampersand project ID or project name. Required on the first call.

Example:

"my-project"

provider
string

The provider that this app connects to. Required on the first call (when sessionId is not present); ignored on resume calls. Conditional requirement is enforced at the application layer.

Example:

"bill"

groupRef
string

Your application's identifier for the organization or workspace that this connection belongs to. Supplied on the first call; ignored on resume calls (the parked flow's identity is used).

Example:

"group-123"

groupName
string

The display name for the group. Defaults to groupRef if not provided. Supplied on the first call; ignored on resume calls.

Example:

"Organization Name"

consumerRef
string

The ID that your app uses to identify the user whose SaaS credential will be used. Supplied on the first call; ignored on resume calls (the parked flow's identity is used).

Example:

"user_123456"

consumerName
string

The display name for the consumer. Defaults to consumerRef if not provided. Supplied on the first call; ignored on resume calls.

Example:

"John Doe"

providerMetadata
Provider Metadata · object

Additional provider-specific metadata collected from the user.

providerAppId
string

ID of the provider app. If omitted, the default provider app set up on the Dashboard is assumed.

Example:

"32356abe-d2fd-49c7-9030-abdcbc6456d4"

customAuth
object

The consumer-supplied custom auth inputs (keyed by CustomAuthInput.name). Supplied on the first call (when sessionId is not present).

Example:
sessionId
string

Identifies an in-progress flow to resume after a redirect. Returned in a prior redirect response. When present, provider and customAuth are not required.

Example:

"7f3c1e2a-9b0d-4a1f-8c2e-1d2f3a4b5c6d"

callbackParams
object

The query/body params the provider sent to the callback, forwarded to resume the flow.

Example:

Response

OK

Response from /custom-auth/connect. Exactly one of redirect or connection is set. A redirect means the client should open the URL and call again with sessionId + callbackParams; a connection means the flow is complete.

redirect
Redirect Response · object
required

Instructs the client to open a URL (e.g. in a popup) to continue a custom auth flow, then resume by calling /custom-auth/connect with the sessionId.