DiyaOS Passwordless identity
DiyaOS Auth
Auth Callback
This route is the shared redirect target for standalone apps and integrated DiyaOS apps.Callback Contract
Allowed redirect route /auth/callback receives authorization results for the OS app during local development.
Production checks State, nonce, PKCE, issuer, audience, redirect URI, origin, and session binding must be validated here.