POST
/api/v1/users/{user}/linkedIdentitiesLink an SSO identity to a user
Links an SSO identity to a user through an identity provider's OAuth flow. Provide the parent user, identity provider, authorization code, and redirect URI; include codeVerifier when the flow uses PKCE.
- IdempotentThe SDK sends
Idempotency-Key, so a retried request is only applied once.
userstringrequired
The identifier of the user associated with the linked identity.
OAuth identity-linking details. The body requires parent, idpName, code, and redirectUri.
parentstringrequired
Required. The parent user who owns the linked identity.
Format: users/{user}
idpNamestringrequired
Required. The identity provider to link.
Format: identity-providers/{idp}
codestringrequired
Required. The authorization code from the identity provider.
redirectUristringrequired
Required. The redirect URI used in the OAuth flow.
codeVerifierstringoptional
Optional. The PKCE code verifier used in the OAuth flow.
200Returns the linked identity resource, including its resource name, identity provider name, and external user identifier.
namestringoptional
The resource name of the linked identity.
Format: users/{user}/linkedIdentities/{linked_identity}
idpNamestringoptional
The resource name of the identity provider.
Format: identity-providers/{idp}
externUidstringoptional
The external user identifier from the identity provider.
defaultDefault error response
codeintegeroptional
The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
messagestringoptional
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
detailsarray<object>optional
A list of messages that carry the error details. There is a common set of message types for APIs to use.
Error handling
The request body requires parent, idpName, code, and redirectUri; use the formats users/{user} for parent and identity-providers/{idp} for idpName. The user path parameter identifies the user, and codeVerifier can be supplied for an OAuth flow that uses PKCE.
