Change how visitors sign in
Switches the method and sets it up. app needs appUrl the first time; oidc needs the provider the first time, and clientSecret can be left out to keep the saved one. Visitors signed in another way are signed out. Admins and owners only.
PATCH
/site/sign-inAuthorization
AuthorizationBearer token · headerrequired`MEDIAN_KEY` from Settings under API, or an MCP OAuth access token. A key acts as the organization; a token acts as the person who approved it.
Request body
requiredapplication/jsonmethodstringrequiredAllowed:
medianappoidcappUrlstringoidcobjectShow propertiesHide properties
issuerstringrequiredclientIdstringrequiredclientSecretstringResponses
200The sign-in settings, as they now read.
methodstringmedian: Median accounts. app: a route in your app. oidc: an OpenID Connect provider.
Allowed:
medianappoidcappUrlstring | nullThe sign-in route in your app, for app.
oidcobject | nullShow propertiesHide properties
issuerstringclientIdstringsecretHintstringThe client secret's last four characters.
oidcRedirectUristringThe redirect URI to register at your OpenID provider.
problemobject | nullWhy your OpenID provider refused the last sign-in. Cleared when a sign-in works or the settings are saved.
Show propertiesHide properties
atnumberWhen it happened, in milliseconds since the epoch.
codestringThe provider's error code, like invalid_scope.
messagestringWhat to change.
detailstring | nullThe provider's own words.
401The bearer token is missing, revoked, or expired.
errorobjectShow propertiesHide properties
codestringmessagestring429Too many requests. Wait the seconds in `Retry-After`. Limits depend on the plan. See [rate limits](/api/errors-and-limits#rate-limits).
errorobjectShow propertiesHide properties
codestringmessagestringRequest
curl -X PATCH "https://api.median.sh/v1/site/sign-in" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"method": "median",
"appUrl": "https://app.example.com/api/median/identity",
"oidc": {
"issuer": "https://example.us.auth0.com",
"clientId": "string",
"clientSecret": "string"
}
}'const response = await fetch("https://api.median.sh/v1/site/sign-in", {
method: "PATCH",
headers: {
"Authorization": "Bearer YOUR_TOKEN",
"Content-Type": "application/json"
},
body: JSON.stringify({
"method": "median",
"appUrl": "https://app.example.com/api/median/identity",
"oidc": {
"issuer": "https://example.us.auth0.com",
"clientId": "string",
"clientSecret": "string"
}
})
});Response
{
"method": "median",
"appUrl": "string",
"oidc": {
"issuer": "string",
"clientId": "string",
"secretHint": "string"
},
"oidcRedirectUri": "string",
"problem": {
"at": 0,
"code": "string",
"message": "string",
"detail": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}