openapi: 3.1.0
info:
title: Proxy Endpoints Metrics Oauth2 API
description: 'HTTP endpoints exposed by oauth2-proxy, a reverse proxy that
authenticates requests using upstream OAuth/OIDC providers. The
OAuth2 endpoints live under a configurable prefix (`--proxy-prefix`,
default `/oauth2`); the health and operational endpoints live at the
document root. Sourced from
https://oauth2-proxy.github.io/oauth2-proxy/features/endpoints.
'
version: '1.0'
servers:
- url: http://localhost:4180
description: Default oauth2-proxy listen address
tags:
- name: Oauth2
paths:
/oauth2/sign_in:
get:
summary: Render sign-in page
responses:
'200':
description: HTML sign-in page.
tags:
- Oauth2
/oauth2/sign_out:
get:
summary: Clear the session cookie
description: Clears the local session and optionally redirects to the provider's logout endpoint.
responses:
'302':
description: Session cleared and user redirected.
tags:
- Oauth2
/oauth2/start:
get:
summary: Begin OAuth authorization
responses:
'302':
description: Redirects to the OAuth provider's authorize endpoint.
tags:
- Oauth2
/oauth2/callback:
get:
summary: OAuth callback target
description: Endpoint the OAuth provider redirects back to after consent.
responses:
'302':
description: Session established and user redirected to the original URL.
tags:
- Oauth2
/oauth2/auth:
get:
summary: External authentication subrequest
description: 'Returns 202 when the request is authenticated and 401 when it is
not, intended for use with `nginx auth_request` or similar
gateways.
'
responses:
'202':
description: Request is authenticated.
'401':
description: Request is not authenticated.
security:
- SessionCookie: []
tags:
- Oauth2
/oauth2/userinfo:
get:
summary: Authenticated user information
responses:
'200':
description: JSON object containing the authenticated user's email and groups.
security:
- SessionCookie: []
tags:
- Oauth2
/oauth2/static/{path}:
parameters:
- in: path
name: path
required: true
schema:
type: string
get:
summary: Serve static assets for the login/error pages
responses:
'200':
description: Static asset (CSS, image, etc.).
tags:
- Oauth2
components:
securitySchemes:
SessionCookie:
type: apiKey
in: cookie
name: _oauth2_proxy
description: Session cookie established by the OAuth callback.