OAuth callback (Google / Apple)
The Cognito Hosted UI's redirect_uri after a Google or Apple sign-in, started at GET /cognito/oauth/{provider}. Not called by API clients directly.
Exchanges code for tokens, provisions or links the profile, sets the access_token, id_token and refresh_token httpOnly cookies, and redirects to the URL carried in state — which is the redirect query parameter given when the flow was started, or the frontend root.
Every failure is also a redirect, to {FRONTEND_URL}/auth?error=…: unverified_account_exists (a provider identity linked to a native account whose address was never verified), missing_code, token_exchange_failed, invalid_token, oauth_error, or the provider's own error with a message.
Parameters
Query Parameters
Authorization code from Cognito.
Where to send the browser after a successful sign-in.
Responses
Redirect — to state on success (with session cookies set), or to /auth?error=… on the frontend.