Oauth2-Proxy Oauth2 API

The Oauth2 API from Oauth2-Proxy — 7 operation(s) for oauth2.

OpenAPI Specification

oauth2-proxy-oauth2-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Proxy Endpoints Metrics Oauth2 API
  description: 'HTTP endpoints exposed by oauth2-proxy, a reverse proxy that

    authenticates requests using upstream OAuth/OIDC providers. The

    OAuth2 endpoints live under a configurable prefix (`--proxy-prefix`,

    default `/oauth2`); the health and operational endpoints live at the

    document root. Sourced from

    https://oauth2-proxy.github.io/oauth2-proxy/features/endpoints.

    '
  version: '1.0'
servers:
- url: http://localhost:4180
  description: Default oauth2-proxy listen address
tags:
- name: Oauth2
paths:
  /oauth2/sign_in:
    get:
      summary: Render sign-in page
      responses:
        '200':
          description: HTML sign-in page.
      tags:
      - Oauth2
  /oauth2/sign_out:
    get:
      summary: Clear the session cookie
      description: Clears the local session and optionally redirects to the provider's logout endpoint.
      responses:
        '302':
          description: Session cleared and user redirected.
      tags:
      - Oauth2
  /oauth2/start:
    get:
      summary: Begin OAuth authorization
      responses:
        '302':
          description: Redirects to the OAuth provider's authorize endpoint.
      tags:
      - Oauth2
  /oauth2/callback:
    get:
      summary: OAuth callback target
      description: Endpoint the OAuth provider redirects back to after consent.
      responses:
        '302':
          description: Session established and user redirected to the original URL.
      tags:
      - Oauth2
  /oauth2/auth:
    get:
      summary: External authentication subrequest
      description: 'Returns 202 when the request is authenticated and 401 when it is

        not, intended for use with `nginx auth_request` or similar

        gateways.

        '
      responses:
        '202':
          description: Request is authenticated.
        '401':
          description: Request is not authenticated.
      security:
      - SessionCookie: []
      tags:
      - Oauth2
  /oauth2/userinfo:
    get:
      summary: Authenticated user information
      responses:
        '200':
          description: JSON object containing the authenticated user's email and groups.
      security:
      - SessionCookie: []
      tags:
      - Oauth2
  /oauth2/static/{path}:
    parameters:
    - in: path
      name: path
      required: true
      schema:
        type: string
    get:
      summary: Serve static assets for the login/error pages
      responses:
        '200':
          description: Static asset (CSS, image, etc.).
      tags:
      - Oauth2
components:
  securitySchemes:
    SessionCookie:
      type: apiKey
      in: cookie
      name: _oauth2_proxy
      description: Session cookie established by the OAuth callback.