guides/web-link-flow.md
Web Link Flow
This runbook describes the implemented /link flow in apps/web.
Supported Inputs
- direct:
serverUrl+apiKey - relay:
relayCode+ optionalrelayUrl
Behavior
- Parse URL params
- Exchange relay code when provided
- Normalize
serverUrl - Verify key via
POST /api/v1/auth/verify - Mark setup complete via
POST /api/v1/auth/link - Persist linked server profile (
mino.linkedServers.v1) - Remove sensitive params from URL
- Redirect to workspace
Security Requirements
- do not log raw API keys
- redact key material in errors/telemetry
- remove
apiKey,relayCode, andrelayUrlfrom URL after processing