Trade a Zoho sign-in’s hand-off for its cookie
const url = 'https://api.sloose.com/auth/zoho/handoff';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"code":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/auth/zoho/handoff \ --header 'Content-Type: application/json' \ --data '{ "code": "example" }'The last step of a page’s Zoho sign-in (/auth/zoho/start?mode=redirect): the page trades the one-use code the completion page put in its address, through its OWN host (/api), and the answer sets the session’s cookie there — Better Auth’s own, which GET /auth/ba/get-session then reads. The code works once, for a minute.
Asked only from one of the app’s own pages: a request whose Origin is not one of them is refused, so no other site can sign a browser in as somebody else.
You never call this directly.
Request Bodyrequired
Section titled “Request Bodyrequired”object
Examplegenerated
{ "code": "example"}Responses
Section titled “Responses”The session’s cookie is set on the host asked through.
object
Example
{ "ok": true}The request — its body or its query — did not match the schema. issues carries the Zod issue list.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}Not asked from one of the app’s own pages (code: BAD_ORIGIN).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No hand-off under that code: it was traded already, its minute passed, or its session has ended (code: HANDOFF_GONE).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}