> This page is for Taurus PROTECT, version v3.48.
> For other versions, use one of these documentation indexes:
> - v3.58 (default): https://taurushq.ferndocs.com/protect-capital/v3.58/llms.txt
> - v3.56: https://taurushq.ferndocs.com/protect-capital/v3.56/llms.txt
> - v3.54: https://taurushq.ferndocs.com/protect-capital/v3.54/llms.txt
> - v3.52: https://taurushq.ferndocs.com/protect-capital/v3.52/llms.txt
> - v3.50: https://taurushq.ferndocs.com/protect-capital/v3.50/llms.txt
> - v3.48: https://taurushq.ferndocs.com/protect-capital/v3.48/llms.txt
> - v3.46: https://taurushq.ferndocs.com/protect-capital/v3.46/llms.txt
> - v3.44: https://taurushq.ferndocs.com/protect-capital/v3.44/llms.txt
> - v3.42: https://taurushq.ferndocs.com/protect-capital/v3.42/llms.txt
> - v3.40: https://taurushq.ferndocs.com/protect-capital/v3.40/llms.txt
> - v3.38: https://taurushq.ferndocs.com/protect-capital/v3.38/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://taurushq.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://taurushq.ferndocs.com/_mcp/server.

# Login flow

## Start Login

This endpoint is necessary for the GUI to detect if the user must log in with a basic email/password setup or be redirected to an SSO identity provider.

Example of call:

```
POST /api/rest/v1/authentication/start_login
{
  "email": "bob@example.com"
}
```

Example of response:

* `mode`: can be` Basic`, `OIDC` or `SAML`

```
{
  "mode": "OIDC"
}
```

The mode returned by the call will define the continuation of the login flow.

## SAML - SSO

This endpoint is called by the GUI to receive the redirection the user must follow in order to get authenticated by the identity provider.

`POST /api/rest/v1/authentication/saml/sso`

Example of request body:

```
{
  "email": "bob@example.com"
}
```

Example of response:

```
302
Location https://idp.example.com/SAML2/Redirect/SSO?SAMLRequest=...&RelayState=...
```

## SAML - ACS

This endpoint is the redirection used by the SAML flow to confirm the authentication of a user.

`POST /api/rest/v1/authentication/saml/acs`

Example of request body:

```
{
  "RelayState": "...",
  "SAMLResponse": "..."
}
```

Example of response:

```
200
Set-Cookie: token=...; HttpOnly; Secure;

{
  "token": "..."
}
```

Diagram below - Calling an endpoint of Taurus-PROTECT with **SAML 2.0**

![](/_fern-img/8b1523cf547f083b8891aa845371d954d2a5142751d77067c4d0a763d1d785a7.webp)

## OIDC - SSO

This endpoint is called by the GUI to receive the redirection the user must follow in order to get authenticated by the identity provider.

POST /api/rest/v1/authentication/oidc/sso

Example of request body:

```
{
  "email": "bob@example.com"
}
```

Example of Response

```
302
Location https://idp.example.com/authorize?redirect_uri=...&client_id=...
```

## OIDC - Token

This endpoint is called by the GUI after it receives a code from the identity provider. Protect can then contact the identity provider to accept the session.

`POST /api/rest/v1/authentication/oidc/token`

Example of request body:

```
{
  "code": "...",
  "state": "..."
}
```

Example of Response

```
200
Set-Cookie: token=...; HttpOnly; Secure;

{
  "token": "..."
}
```

Diagram below - Calling an endpoint of Taurus-PROTECT with **OIDC**

![](/_fern-img/bf249a46fb19ef021025e7c259e58c484c1a8c5d8d046a16905b7e21b5b5559f.webp)

#