Browse the API reference

Complete SSO Authentication

post/v1/auth/sso-complete

Part of Auth.

Step 3 of 3. Exchanges the session ID for a full JWT token. Called by the target app after redirect.

Authentication

This operation does not require an API key.

Request body

Required, application/json.

FieldTypeDescription
session_idrequiredstring

Temporary session ID from secure handoff

Example request

curl
curl -X POST "https://api.robosystems.ai/v1/auth/sso-complete" \
  -H "Content-Type: application/json" \
  -d '{
  "session_id": "string"
}'

Responses

200 Successful Response

FieldTypeDescription
userrequiredobject

User information

orgoptionalobject

Organization information (personal org created automatically on registration)

messagerequiredstring

Success message

statusoptionalstring

Login flow state: authenticated (token present), or a passkey MFA step is required before a session is issued (mfa_token present)

One of: authenticated, mfa_required, mfa_enrollment_required

Default: authenticated

mfa_tokenoptionalstring

Short-lived token authorizing the MFA second step or forced enrollment; present only when status is not 'authenticated'

tokenoptionalstring

JWT authentication token (optional for cookie-based auth)

expires_inoptionalinteger

Token expiry time in seconds from now

refresh_thresholdoptionalinteger

Recommended refresh threshold in seconds before expiry

StatusMeaning
400Invalid request
422Validation Error
429Rate limit exceeded
500Internal server error