Skip to main content
Exchange a Google OAuth2 access token for a BlobHub token pair. The access token is the entire request. Who it belongs to is established server-side against Google — the token’s audience is checked to confirm it was issued to BlobHub, and the account it signs in is read from Google’s profile response. Nothing about the identity is taken from the request body.

POST /auth/google/signin

Request Body

This body accepts no other fields. email, name and external_id were previously required and are no longer accepted at all — a request carrying any of them is rejected with 400 invalid_request_body. The email, name and Google id of the account are read from Google directly.

Response

Errors

Example