curl --request POST \
--url https://mcp.echozero.app/api/auth/social/verify \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"state": "550e8400-e29b-41d4-a716-446655440000"
}
'{
"success": true,
"data": {
"status": "success",
"newUser": true,
"onBoardingCompleted": true,
"mfaRequired": true,
"user": {
"id": "507f1f77bcf86cd799439011",
"username": "alice_bob",
"email": "alice@example.com",
"languageCode": "EN",
"emailVerifiedAt": "2023-11-07T05:31:56Z"
},
"tokens": {
"accessToken": "<string>",
"refreshToken": "<string>",
"mfaAccessToken": "<string>"
},
"errorMessage": "<string>",
"unlocksAt": "2023-11-07T05:31:56Z"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Auth
Verify an OAuth callback and issue tokens
Call this endpoint after the OAuth provider redirects back with code and state. Returns the same payload as /auth/verify.
POST
/
api
/
auth
/
social
/
verify
curl --request POST \
--url https://mcp.echozero.app/api/auth/social/verify \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"state": "550e8400-e29b-41d4-a716-446655440000"
}
'{
"success": true,
"data": {
"status": "success",
"newUser": true,
"onBoardingCompleted": true,
"mfaRequired": true,
"user": {
"id": "507f1f77bcf86cd799439011",
"username": "alice_bob",
"email": "alice@example.com",
"languageCode": "EN",
"emailVerifiedAt": "2023-11-07T05:31:56Z"
},
"tokens": {
"accessToken": "<string>",
"refreshToken": "<string>",
"mfaAccessToken": "<string>"
},
"errorMessage": "<string>",
"unlocksAt": "2023-11-07T05:31:56Z"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Headers
Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.
Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.
Body
application/json
OpenAPI schema McpVerifySocialAuthBodyDto.