> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trylath.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Every Lath operation is POST https://platform.trylath.com/<operation name with dots replaced by slashes>, with a JSON body and `Authorization: Bearer <key>`. `email.send` is POST /email/send.
> Branch on `error.code`, never on `error.message`. Every refusal also carries `error.fix`, which names the next step.
> Send an `Idempotency-Key` header on any operation that is not retry-safe, so a retry cannot run it twice.
> A `lath_test_` key emails only the account's own members and sends no SMS; a `lath_live_` key reaches real recipients and is billed.
> The OpenAPI document, generated from the same registry as the routes, is at https://platform.trylath.com/openapi.json.

# auth.oauth.start

> Begins a sign-in with Google, Microsoft or GitHub. Returns the URL to send the person to, and the challenge id the callback needs. The state is single-use and bound to this environment and this provider; the PKCE verifier never leaves Lath. Refuses when the method is turned off for this environment, or when neither this project nor the deployment has an app registered for that provider.



## OpenAPI

````yaml /api-reference/openapi.json post /auth/oauth/start
openapi: 3.1.0
info:
  title: Lath API
  version: 0.1.0
  description: >-
    Every operation is one POST. The same set is reachable over MCP, the SDK and
    the CLI; nothing is dashboard-only.
servers:
  - url: https://platform.trylath.com
    description: This deployment
security: []
paths:
  /auth/oauth/start:
    post:
      tags:
        - auth
      summary: auth.oauth.start
      description: >-
        Begins a sign-in with Google, Microsoft or GitHub. Returns the URL to
        send the person to, and the challenge id the callback needs. The state
        is single-use and bound to this environment and this provider; the PKCE
        verifier never leaves Lath. Refuses when the method is turned off for
        this environment, or when neither this project nor the deployment has an
        app registered for that provider.
      operationId: auth.oauth.start
      parameters:
        - name: Idempotency-Key
          in: header
          required: false
          schema:
            type: string
          description: >-
            Replays the stored response for the same key and input; refuses
            different input.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                provider:
                  type: string
                  enum:
                    - google
                    - microsoft
                    - github
                redirectTo:
                  description: >-
                    Where to send the person after sign-in; must be an allowed
                    origin
                  type: string
                  maxLength: 2000
              required:
                - provider
              additionalProperties: false
      responses:
        '200':
          description: '{ activityId, result }. activityId is empty for reads.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  activityId:
                    type: string
                    description: The activity this call created, or empty for a read.
                  result:
                    $schema: https://json-schema.org/draft/2020-12/schema
                    type: object
                    properties:
                      challengeId:
                        type: string
                        format: uuid
                        pattern: >-
                          ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                      url:
                        type: string
                      state:
                        type: string
                      provider:
                        type: string
                      expiresInSeconds:
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                    required:
                      - challengeId
                      - url
                      - state
                      - provider
                      - expiresInSeconds
                    additionalProperties: {}
                required:
                  - activityId
                  - result
        '400':
          description: invalid_input or invalid_json
        '401':
          description: unauthenticated
        '403':
          description: forbidden
        '404':
          description: not_found
        '409':
          description: 'conflict: idempotency_mismatch, email_taken, last_key'
        '413':
          description: body_too_large
        '429':
          description: rate_limited
      security:
        - bearer: []
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: >-
        A Lath API key: lath_live_sk… or lath_test_sk… on a server,
        lath_live_pk… or lath_test_pk… in a browser.

````