PATCH /site/sign-in
Updated Oct 2, 20261 minute read
Change how visitors sign in
Switches the method and sets it up. app needs appUrl the first time; oidc needs the provider the first time, and clientSecret can be left out to keep the saved one. Visitors signed in another way are signed out. Admins and owners only.
Part of Site.
Request body
application/json, required.
| Field | Type | Required | Description |
|---|---|---|---|
method | "median" | "app" | "oidc" | Yes | |
appUrl | string | No | |
oidc | object | No | |
oidc.issuer | string | Yes | |
oidc.clientId | string | Yes | |
oidc.clientSecret | string | No |
Responses
| Status | Description |
|---|---|
200 | The sign-in settings, as they now read. |
401 | The bearer token is missing, revoked, or expired. |
429 | Too many requests. Wait the seconds in Retry-After. Limits depend on the plan. See rate limits. |
200 body
| Field | Type | Required | Description |
|---|---|---|---|
method | "median" | "app" | "oidc" | No | median: Median accounts. app: a route in your app. oidc: an OpenID Connect provider. |
appUrl | any | No | The sign-in route in your app, for app. |
oidc | object | No | |
oidc.issuer | string | No | |
oidc.clientId | string | No | |
oidc.secretHint | string | No | The client secret's last four characters. |
oidcRedirectUri | string | No | The redirect URI to register at your OpenID provider. |
problem | object | No | Why your OpenID provider refused the last sign-in. Cleared when a sign-in works or the settings are saved. |
problem.at | number | No | When it happened, in milliseconds since the epoch. |
problem.code | string | No | The provider's error code, like invalid_scope. |
problem.message | string | No | What to change. |
problem.detail | any | No | The provider's own words. |
Example request
curl -X PATCH https://api.median.sh/v1/site/sign-in \
-H "Authorization: Bearer $BEARER_AUTH"