Skip to content

Trade a Zoho sign-in’s hand-off for its cookie

POST
/auth/zoho/handoff
curl --request POST \
--url https://api.sloose.com/auth/zoho/handoff \
--header 'Content-Type: application/json' \
--data '{ "code": "example" }'

The last step of a page’s Zoho sign-in (/auth/zoho/start?mode=redirect): the page trades the one-use code the completion page put in its address, through its OWN host (/api), and the answer sets the session’s cookie there — Better Auth’s own, which GET /auth/ba/get-session then reads. The code works once, for a minute.

Asked only from one of the app’s own pages: a request whose Origin is not one of them is refused, so no other site can sign a browser in as somebody else.

You never call this directly.

Media typeapplication/json
object
code
required
string
>= 1 characters <= 200 characters
Examplegenerated
{
"code": "example"
}

The session’s cookie is set on the host asked through.

Media typeapplication/json
object
ok
required
boolean
Example
{
"ok": true
}

The request — its body or its query — did not match the schema. issues carries the Zod issue list.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Not asked from one of the app’s own pages (code: BAD_ORIGIN).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No hand-off under that code: it was traded already, its minute passed, or its session has ended (code: HANDOFF_GONE).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page