openapi: 3.1.0 info: title: Proxy Endpoints Metrics Oauth2 API description: 'HTTP endpoints exposed by oauth2-proxy, a reverse proxy that authenticates requests using upstream OAuth/OIDC providers. The OAuth2 endpoints live under a configurable prefix (`--proxy-prefix`, default `/oauth2`); the health and operational endpoints live at the document root. Sourced from https://oauth2-proxy.github.io/oauth2-proxy/features/endpoints. ' version: '1.0' servers: - url: http://localhost:4180 description: Default oauth2-proxy listen address tags: - name: Oauth2 paths: /oauth2/sign_in: get: summary: Render sign-in page responses: '200': description: HTML sign-in page. tags: - Oauth2 /oauth2/sign_out: get: summary: Clear the session cookie description: Clears the local session and optionally redirects to the provider's logout endpoint. responses: '302': description: Session cleared and user redirected. tags: - Oauth2 /oauth2/start: get: summary: Begin OAuth authorization responses: '302': description: Redirects to the OAuth provider's authorize endpoint. tags: - Oauth2 /oauth2/callback: get: summary: OAuth callback target description: Endpoint the OAuth provider redirects back to after consent. responses: '302': description: Session established and user redirected to the original URL. tags: - Oauth2 /oauth2/auth: get: summary: External authentication subrequest description: 'Returns 202 when the request is authenticated and 401 when it is not, intended for use with `nginx auth_request` or similar gateways. ' responses: '202': description: Request is authenticated. '401': description: Request is not authenticated. security: - SessionCookie: [] tags: - Oauth2 /oauth2/userinfo: get: summary: Authenticated user information responses: '200': description: JSON object containing the authenticated user's email and groups. security: - SessionCookie: [] tags: - Oauth2 /oauth2/static/{path}: parameters: - in: path name: path required: true schema: type: string get: summary: Serve static assets for the login/error pages responses: '200': description: Static asset (CSS, image, etc.). tags: - Oauth2 components: securitySchemes: SessionCookie: type: apiKey in: cookie name: _oauth2_proxy description: Session cookie established by the OAuth callback.