v16

OpenAPI 3.0.3Apache 2.0raw.githubusercontent.com2026-04-0886158866.0 KB
CIBA

Fail Backchannel Authentication Request

The API prepares JSON that contains an error. The JSON should be used as the response body of the response which is returned to the client from the backchannel authentication endpoint.

post/api/{serviceId}/backchannel/authentication/fail

Path parameters

serviceIdstring required

A service ID.

Request body

ticketstring required

The ticket which should be deleted on a call of Authlete's /backchannel/authentication/fail API. This request parameter is not mandatory but optional. If this request parameter is given and the ticket belongs to the service, the specified ticket is deleted from the database. Giving this parameter is recommended to clean up the storage area for the service.

reason'ACCESS_DENIED' | 'EXPIRED_LOGIN_HINT_TOKEN' | 'INVALID_BINDING_MESSAGE' | 'INVALID_TARGET' | 'INVALID_USER_CODE' | 'MISSING_USER_CODE' | 'SERVER_ERROR' | 'UNAUTHORIZED_CLIENT' | 'UNKNOWN_USER_ID' required

The reason of the failure of the backchannel authentication request. This request parameter is not mandatory but optional. However, giving this parameter is recommended. If omitted, SERVER_ERROR is used as a reason.

errorDescriptionstring

The description of the error. This corresponds to the error_description property in the response to the client.

errorUristring

The URI of a document which describes the error in detail. If this optional request parameter is given, its value is used as the value of the error_uri property.

Response

resultCodestring

The code which represents the result of the API call.

resultMessagestring

A short message which explains the result of the API call.

action'INTERNAL_SERVER_ERROR' | 'BAD_REQUEST' | 'FORBIDDEN'

The next action that the authorization server implementation should take.

responseContentstring

The content that the authorization server implementation is to return to the client application. Its format varies depending on the value of action parameter.