Memos unofficial
POST/api/v1/users/{user}/linkedIdentities

Link an SSO identity to a user

Links an SSO identity to a user through an identity provider's OAuth flow. Provide the parent user, identity provider, authorization code, and redirect URI; include codeVerifier when the flow uses PKCE.

  • IdempotentThe SDK sends Idempotency-Key, so a retried request is only applied once.

1 parameter · 5 body fields
userstringrequired
The identifier of the user associated with the linked identity.

OAuth identity-linking details. The body requires parent, idpName, code, and redirectUri.

parentstringrequired
Required. The parent user who owns the linked identity. Format: users/{user}
idpNamestringrequired
Required. The identity provider to link. Format: identity-providers/{idp}
codestringrequired
Required. The authorization code from the identity provider.
redirectUristringrequired
Required. The redirect URI used in the OAuth flow.
codeVerifierstringoptional
Optional. The PKCE code verifier used in the OAuth flow.

2 status codes
200Returns the linked identity resource, including its resource name, identity provider name, and external user identifier.
namestringoptional
The resource name of the linked identity. Format: users/{user}/linkedIdentities/{linked_identity}
idpNamestringoptional
The resource name of the identity provider. Format: identity-providers/{idp}
externUidstringoptional
The external user identifier from the identity provider.
defaultDefault error response
codeintegeroptional
The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
messagestringoptional
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
detailsarray<object>optional
A list of messages that carry the error details. There is a common set of message types for APIs to use.

Error handling

The request body requires parent, idpName, code, and redirectUri; use the formats users/{user} for parent and identity-providers/{idp} for idpName. The user path parameter identifies the user, and codeVerifier can be supplied for an OAuth flow that uses PKCE.