OUTCOME · Create or advance
What changes
Creates or advances only the federated authorization resource described by this contract after authorization, validation, policy, and idempotency gates pass.
v2Identity sessions and federation
/api/v2/auth/federation/{provider}/authorizationsPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this when an identity, compliance, relying-party, or trust agent workflow needs to apply the documented federated authorization transition after re-reading the current authoritative state so it can make a purpose-limited identity or assurance decision with current policy and lifecycle state.
OUTCOME · Create or advance
Creates or advances only the federated authorization resource described by this contract after authorization, validation, policy, and idempotency gates pass.
WHY IT MATTERS
ISOLATION + AUTHORITY
Bearer subject, tenant, purpose, policy version, role, issuer, reviewer, provider, and relying-party boundaries remain distinct. The response or transition grants no payment, custody, settlement, publisher, matching, or trading authority and must not expose regulated evidence beyond the live schema.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
providerpathRequiredgoogle | apple | githubConfigured provider adapter.
AuthorizationheaderOptionalBearer tokenRequired only for mode=link.
tenant_uuidbodyOptionalidentifierTenant policy boundary; defaults to global.
modebodyRequiredlogin | linkStart a login or explicit existing-account link.
redirect_uribodyRequiredexact registered HTTPS URIMust exactly match the Identity allowlist and provider registration.
return_tobodyOptionallocal absolute pathLocal post-login navigation target; external URLs are rejected.
step_up_tokenbodyOptionalhcsu_ tokenRequired for mode=link and consumed for FEDERATED_IDENTITY_LINK.
REQUEST
{
"tenant_uuid": "global",
"mode": "login",
"redirect_uri": "https://hybrid-chain.com/auth/callback",
"return_to": "/account"
}STABLE ERROR CODES
These codes are published by the authoritative gateway contract for this endpoint. Treat message as safe diagnostic text; integrations should branch on code and HTTP status.
invalid_jsonThe JSON body is malformed or fails the published identity-security schema.invalid_security_requestThe session, scope, public key, proof, or purpose-bound security request is invalid.invalid_credentialsThe bearer, client assertion, or proof-of-possession credential is invalid.step_up_requiredFresh purpose-bound authenticator verification or stronger authority is required.signing_key_not_foundThe requested signing-key or workload-client resource was not found.security_conflictThe requested identity-security transition conflicts with current state.identity_security_unavailableThe authoritative Identity security service is temporarily unavailable.RESPONSES
{
"data": {
"transaction_id": "9b51ed4c9c8f4aec85d1bd5520e40557",
"provider": "google",
"mode": "login",
"authorization_url": "https://accounts.google.com/o/oauth2/v2/auth?…",
"state": "hcfed_…",
"expires_in": 600,
"return_to": "/account"
}
}{
"code": "invalid_session_request",
"message": "The provider, redirect URI, or return target is invalid."
}invalid_session_request{
"code": "session_action_forbidden",
"message": "The provider is disabled or linking lacks step-up."
}session_action_forbidden{
"code": "identity_unavailable",
"message": "Identity or provider configuration is unavailable."
}identity_unavailableOPERATIONAL NOTES
UPGRADING FROM V1
If you maintain an older integration, use this map to find the V2 replacement. Do not translate the old request field-for-field: rebuild it from the V2 parameters and schemas above because identity, authorization, replay protection, and response semantics may have changed.
/api/v1/auth/federateAUTH: Generate Web-Federation TokenThis route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗