Start a sajn Login session
Create a hosted login session and get a URL to send the user to.
Use this when you don’t want to run an OIDC client — typically a native app that opens loginUrl in an in-app browser.
Flow:
POSThere to getloginUrl- Open it; the user authenticates with BankID on sajn’s hosted page
- We redirect to your
redirectUriwith?sessionId=…(and?state=…if you sent one) GET /api/v1/login/sessions/{id}from your server to read the result
The redirect is only a handle. Never trust it as proof of authentication — anyone can craft that URL. The server-side GET is the authoritative read, because it is authenticated as your organization.
redirectUri must be registered on the client. Custom schemes (myapp://auth) are supported so the in-app browser can dismiss straight back into your app.
Authorizations
Personal API key, e.g. Authorization: Bearer sajn_sk_.... Not scope-limited — acts as the issuing user.
Headers
Bearer token for API authentication
Makes retries safe. A retry with the same key and the same request replays the stored response for 24 hours (header Idempotent-Replayed: true); the same key with a different request returns 400.
255Body
Body
The sajn Login client to authenticate against.
1Where to send the user when authentication finishes. Must be registered on the client.
1Opaque value echoed back on the redirect and in the session result.
512
