OAuth provider redirect target (not called directly)
Hit by the OAuth provider’s browser redirect, never called directly
by a dev/integration. Unauthenticated by design: this request carries no
Authorization header (it’s a browser navigation, not an API call) — the
single-use, unguessable state value is itself the capability that
authorizes completing this specific pending flow, the same model
repositories/_stream_tokens.py’s media-stream auth tokens use. Always
redirects to the dashboard rather than returning raw JSON, success or
failure.
Authorizations
A long-lived, privileged API key (ek_... prefix), minted once from the dashboard. Intended for trusted server-side use only; never expose it in client-side code. Send as Authorization: Bearer ek_.... Required by every Calls, Batches, Agents, Tools, MCP Servers, Documents, and Realtime route.
Response
Successful Response