Exchanges a social provider token for an InCrowd / FanScore access token.
The providerToken is validated against the named provider — a Google or Apple id_token, or a Facebook access token — using the configuration registered for the supplied clientId. If the provider identity has not been seen before, a Cortex SSO user is provisioned from the profile returned by the provider and a mapping is stored; otherwise the existing mapping is used.
The endpoint is unauthenticated: the providerToken in the body is the only credential.
Some clients require a first and last name on the provider profile before a new user can be created. Where the provider does not return them — Apple only supplies them on first authorisation — pass them in metadata.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
