latestOpenAPI 3.1.02026-08-223321,1001.6 MB
2134ebffd1ef
Silent Authenticate
Exchange a one-time silent authorization code and rotate cookies.
The legacy (routing-disabled) branch also backs same-account organization switching -- including the audited platform-admin cross-organization escalation in AuthService.resolve_token_membership -- so the submitted token's authorized organization is intentionally allowed to differ from authenticated_user's current organization. Only the underlying account (sub and, once resolved, decision.user.id) must match; which organization that account is authorized to reach for is decided exclusively by resolve_token_membership, not re-derived here.
post/authenticate/silent
Request body
Response
Successful Response