> ## Documentation Index
> Fetch the complete documentation index at: https://docs.purplelabelmd.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Complete login and start the patient session

> Completes the hosted login: it validates the returned login state, exchanges the authorization code for tokens, and starts an encrypted, HttpOnly session cookie for your patient. On success the patient is redirected to the return URL from the login step; on any failure both cookies are cleared and the patient is redirected to a safe page with no error detail. The session is short-lived and carries no patient data.



## OpenAPI

````yaml /openapi/public-openapi.json get /v1/auth/callback
openapi: 3.1.0
info:
  title: Purple API
  version: 0.0.0
servers:
  - url: https://api.dev.purplelabelmd.com
security: []
tags:
  - description: Sign a patient in and out and manage the browser session.
    name: Sessions & authentication
  - description: Run the server-driven intake questionnaire question by question.
    name: Intake
  - description: Address autocomplete for the intake flow.
    name: Addresses
  - description: Read the public status of a patient's enrollment.
    name: Enrollment
  - description: Track a client's onboarding progress.
    name: Onboarding
  - description: Read back the platform configuration stored for your brand.
    name: Brand configuration
  - description: Enable offerings for your brand and set their display copy.
    name: Offering configuration
  - description: Start and track payments for an order.
    name: Payments
  - description: Subscribe to platform events and manage delivery endpoints.
    name: Webhooks
paths:
  /v1/auth/callback:
    get:
      tags:
        - Sessions & authentication
      summary: Complete login and start the patient session
      description: >-
        Completes the hosted login: it validates the returned login state,
        exchanges the authorization code for tokens, and starts an encrypted,
        HttpOnly session cookie for your patient. On success the patient is
        redirected to the return URL from the login step; on any failure both
        cookies are cleared and the patient is redirected to a safe page with no
        error detail. The session is short-lived and carries no patient data.
      operationId: authCallback
      parameters:
        - in: query
          name: code
          required: false
          schema:
            type: string
        - in: query
          name: state
          required: false
          schema:
            type: string
        - $ref: '#/components/parameters/CorrelationIdHeader'
      responses:
        '302':
          description: >-
            on success sets the session cookie and redirects to returnTo; on
            failure clears cookies
          headers:
            Location:
              schema:
                type: string
            Set-Cookie:
              schema:
                type: string
        '429':
          $ref: '#/components/responses/EdgeRateLimited'
      security: []
components:
  parameters:
    CorrelationIdHeader:
      description: >-
        An optional id you send to tie this request to your own logs. Send one
        and it is echoed back unchanged; omit it and one is assigned for you.
        Either way the id is returned in the X-Correlation-Id response header on
        every response, including errors, so you can match a response to the
        request that produced it.
      in: header
      name: X-Correlation-Id
      required: false
      schema:
        maxLength: 128
        pattern: ^[A-Za-z0-9][A-Za-z0-9._:-]*$
        type: string
  responses:
    EdgeRateLimited:
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/EdgeProblem'
      description: >-
        Too many requests. You have exceeded the request rate allowed for this
        endpoint. Wait the number of seconds given in the Retry-After response
        header, then retry the request.
      headers:
        Retry-After:
          description: Seconds to wait before you retry.
          schema:
            type: integer
        X-Correlation-Id:
          description: The correlation id for this request, echoed back.
          schema:
            type: string
  schemas:
    EdgeProblem:
      description: RFC 7807 problem+json error body.
      properties:
        detail:
          type: string
        status:
          type: integer
        title:
          type: string
        type:
          format: uri-reference
          type: string
      required:
        - type
        - title
        - status
      type: object

````