Auth control plane
DiyaOS Passwordless identity

DiyaOS Auth

Auth Callback

This route is the shared redirect target for standalone apps and integrated DiyaOS apps.

Callback Contract

Allowed redirect route /auth/callback receives authorization results for the OS app during local development.
Production checks State, nonce, PKCE, issuer, audience, redirect URI, origin, and session binding must be validated here.