Exchange a protected reverse-proxy assertion for a local session
POST/api/v1/auth/trusted-proxy/:provider_id/session
Accepted only from a configured direct proxy peer supplying the deployment secret and bounded identity headers. Client-supplied identity headers alone are never authority.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 503
Opaque local browser session issued
The multipart shape or Idempotency-Key is malformed
The opaque credential is absent, ambiguous, malformed, expired, revoked, or invalid
The browser mutation did not originate from this application, or the authenticated member lacks the required permission
Trusted-proxy provider is disabled
A required core dependency is unavailable; retry with bounded backoff