GET /api/auth/magic/pending - the waiting window's view of its own request. Never a hash, never a code; `unknown` for a browser without a request.
const url = 'https://example.com/api/auth/magic/pending';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/api/auth/magic/pendingResponses
Section titled “Responses”State of the magic-link request bound to this browser
What the waiting window may learn about its own request.
object
When the device code stops being accepted; only while code_required.
pending | code_required | completed | expired | invalidated |
unknown (this browser holds no request the server knows).
Examplegenerated
{ "code_expires_at": "2026-04-15T12:00:00Z", "status": "example"}Structured server error
The canonical JSON body of every error response — the single source of truth
the frontend binds to. Every AppError serializes as this exact shape, and
the generated OpenAPI component ApiErrorBody (with its ErrorCode enum) is
what the frontend error schema is generated from, so there is no hand-written
error schema on either end.
object
Machine-readable, stable error code.
Present only on a quota-exceeded 403 — the inline upgrade-CTA payload.
object
The entitlement feature key that was hit, e.g. apps.max_count.
The plan’s limit for this key.
Where to send the user to upgrade.
Current usage (count or bytes, per the key).
Human-readable message (the server’s English text; the client may localize
by code).
Example
{ "code": "not_found"}