Median

PATCH /site/sign-in

Updated Oct 2, 20261 minute read

Change how visitors sign in

Switches the method and sets it up. app needs appUrl the first time; oidc needs the provider the first time, and clientSecret can be left out to keep the saved one. Visitors signed in another way are signed out. Admins and owners only.

Part of Site.

Request body

application/json, required.

FieldTypeRequiredDescription
method"median" | "app" | "oidc"Yes
appUrlstringNo
oidcobjectNo
oidc.issuerstringYes
oidc.clientIdstringYes
oidc.clientSecretstringNo

Responses

StatusDescription
200The sign-in settings, as they now read.
401The bearer token is missing, revoked, or expired.
429Too many requests. Wait the seconds in Retry-After. Limits depend on the plan. See rate limits.

200 body

FieldTypeRequiredDescription
method"median" | "app" | "oidc"Nomedian: Median accounts. app: a route in your app. oidc: an OpenID Connect provider.
appUrlanyNoThe sign-in route in your app, for app.
oidcobjectNo
oidc.issuerstringNo
oidc.clientIdstringNo
oidc.secretHintstringNoThe client secret's last four characters.
oidcRedirectUristringNoThe redirect URI to register at your OpenID provider.
problemobjectNoWhy your OpenID provider refused the last sign-in. Cleared when a sign-in works or the settings are saved.
problem.atnumberNoWhen it happened, in milliseconds since the epoch.
problem.codestringNoThe provider's error code, like invalid_scope.
problem.messagestringNoWhat to change.
problem.detailanyNoThe provider's own words.

Example request

curl -X PATCH https://api.median.sh/v1/site/sign-in \
  -H "Authorization: Bearer $BEARER_AUTH"

Still need help?

    Esc