Login flow
Start Login
This endpoint is necessary for the GUI to detect if the user must log in with a basic email/password setup or be redirected to an SSO identity provider.
Example of call:
Example of response:
mode: can beBasic,OIDCorSAML
The mode returned by the call will define the continuation of the login flow.
SAML - SSO
This endpoint is called by the GUI to receive the redirection the user must follow in order to get authenticated by the identity provider.
POST /api/rest/v1/authentication/saml/sso
Example of request body:
Example of response:
SAML - ACS
This endpoint is the redirection used by the SAML flow to confirm the authentication of a user.
POST /api/rest/v1/authentication/saml/acs
Example of request body:
Example of response:
Diagram below - Calling an endpoint of Taurus-PROTECT with SAML 2.0

OIDC - SSO
This endpoint is called by the GUI to receive the redirection the user must follow in order to get authenticated by the identity provider.
POST /api/rest/v1/authentication/oidc/sso
Example of request body:
Example of Response
OIDC - Token
This endpoint is called by the GUI after it receives a code from the identity provider. Protect can then contact the identity provider to accept the session.
POST /api/rest/v1/authentication/oidc/token
Example of request body:
Example of Response
Diagram below - Calling an endpoint of Taurus-PROTECT with OIDC
