Skip to content

Where the owner's browser lands. The state names the pending row and is its whole credential: unguessable, taken once, dead after its window. The code is exchanged, the token set sealed under the connection's own secret, the catalog read with it, and the connection linked.

GET
/connections/callback
curl --request GET \
--url 'https://api.canopyhq.dev/connections/callback?state=example'
state
required
string

The state the authorization was started with.

code
string

The authorization code, on a grant.

iss
string

The issuer, when the server sends it.

error
string

Why the authorization was refused, on a refusal.

Linked, or refused by the owner; a line of text says which.

Linked; the browser is sent where the link asked.

No authorization pending under that state.

The state was already taken, or its window passed.

The token or the catalog could not be read from the server.