> ## Documentation Index
> Fetch the complete documentation index at: https://docs.photon.codes/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use Stable documentation by default. Honor an explicit Beta request or a URL under /docs/beta/. If the requested version conflicts with the installed CLI package or API origin, clarify the target before writing integration code.
> Pages under /docs/beta/ document Beta; other product pages document Stable. Keep the CLI package, commands, API origin, and credentials within the selected version. State the documentation version in your answer.
> For MCP search, always pass version: Stable or version: Beta. Unfiltered search mixes both versions. For filesystem reads, keep Beta queries under /beta/ and exclude /beta/ from Stable queries; discover paths before reading them.
> The public docs base is https://photon.codes/docs. Convert MCP page paths to public URLs under that base, preserving /beta/ when present. Read https://photon.codes/docs/skill.md for version selection and https://photon.codes/docs/llms.txt for the version indexes.

# Start company sign-in

> Returns a sign-in URL without requiring an existing account: the company SSO connection when the target has a ready connection, otherwise ordinary account login. Supply one documented enrollment variant: organizationId with returnTo (optionally invitationToken), invitationToken with returnTo, or retryToken. Open the returned URL to continue authentication; receiving a URL does not complete sign-in. This is a browser flow: the request must come from an allowed Origin, and the retryToken variant also needs the retry cookie set by the failed sign-in, so send it with credentials.



## OpenAPI

````yaml https://api.photon.codes/openapi.json post /v1/auth/login/enrollment
openapi: 3.1.0
info:
  title: Photon API
  version: 1.0.0
servers:
  - url: https://api.photon.codes
security: []
paths:
  /v1/auth/login/enrollment:
    post:
      tags:
        - Authentication
      summary: Start company sign-in
      description: >-
        Returns a sign-in URL without requiring an existing account: the company
        SSO connection when the target has a ready connection, otherwise
        ordinary account login. Supply one documented enrollment variant:
        organizationId with returnTo (optionally invitationToken),
        invitationToken with returnTo, or retryToken. Open the returned URL to
        continue authentication; receiving a URL does not complete sign-in. This
        is a browser flow: the request must come from an allowed Origin, and the
        retryToken variant also needs the retry cookie set by the failed
        sign-in, so send it with credentials.
      operationId: startEnterpriseLogin
      parameters: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/StartEnterpriseLoginRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StartEnterpriseLoginResponse'
          description: >-
            Company SSO URL when the target has a ready connection, otherwise
            the ordinary Account login URL. The response never says which, and
            access is decided only after authentication.
          headers:
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Idempotent-Replayed:
              $ref: '#/components/headers/Idempotent-Replayed'
            Link:
              $ref: '#/components/headers/Link'
            RateLimit:
              $ref: '#/components/headers/RateLimit'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-Request-ID:
              $ref: '#/components/headers/X-Request-ID'
            X-Trace-ID:
              $ref: '#/components/headers/X-Trace-ID'
        '400':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/InvalidReturnToProblem'
          description: 'INVALID_RETURN_TO: Invalid Return To'
          headers:
            Deprecation:
              $ref: '#/components/headers/Deprecation'
            Idempotent-Replayed:
              $ref: '#/components/headers/Idempotent-Replayed'
            Link:
              $ref: '#/components/headers/Link'
            RateLimit:
              $ref: '#/components/headers/RateLimit'
            RateLimit-Policy:
              $ref: '#/components/headers/RateLimit-Policy'
            Retry-After:
              $ref: '#/components/headers/Retry-After'
            Sunset:
              $ref: '#/components/headers/Sunset'
            X-Request-ID:
              $ref: '#/components/headers/X-Request-ID'
            X-Trace-ID:
              $ref: '#/components/headers/X-Trace-ID'
      security: []
components:
  schemas:
    StartEnterpriseLoginRequest:
      anyOf:
        - $ref: '#/components/schemas/OrganizationEnterpriseLoginRequest'
        - $ref: '#/components/schemas/InvitationEnterpriseLoginRequest'
        - $ref: '#/components/schemas/RetryEnterpriseLoginRequest'
    StartEnterpriseLoginResponse:
      additionalProperties: {}
      properties:
        url:
          format: uri
          type: string
      required:
        - url
      type: object
    InvalidReturnToProblem:
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
      example:
        code: INVALID_RETURN_TO
        status: 400
        title: Invalid Return To
        type: https://photon.codes/docs/problems/invalid-return-to
      properties:
        code:
          const: INVALID_RETURN_TO
          type: string
        detail:
          minLength: 1
          type: string
        instance:
          minLength: 1
          type: string
        remediation:
          not: {}
        requestId:
          minLength: 1
          type: string
        status:
          const: 400
          type: number
        title:
          const: Invalid Return To
          type: string
        type:
          const: https://photon.codes/docs/problems/invalid-return-to
          type: string
      required:
        - code
        - status
        - title
        - type
      type: object
    OrganizationEnterpriseLoginRequest:
      additionalProperties: false
      properties:
        invitationToken:
          pattern: ^[A-Za-z0-9_-]{43}$
          type: string
        organizationId:
          pattern: ^pho_org_[0-7][0-9a-hjkmnp-tv-z]{25}$
          type: string
        returnTo:
          maxLength: 2048
          minLength: 1
          type: string
      required:
        - organizationId
        - returnTo
      type: object
    InvitationEnterpriseLoginRequest:
      additionalProperties: false
      properties:
        invitationToken:
          pattern: ^[A-Za-z0-9_-]{43}$
          type: string
        returnTo:
          maxLength: 2048
          minLength: 1
          type: string
      required:
        - invitationToken
        - returnTo
      type: object
    RetryEnterpriseLoginRequest:
      additionalProperties: false
      properties:
        retryToken:
          pattern: >-
            ^enroll_[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
          type: string
      required:
        - retryToken
      type: object
    JsonValue:
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - items:
            $ref: '#/components/schemas/JsonValue'
          type: array
        - additionalProperties:
            $ref: '#/components/schemas/JsonValue'
          propertyNames:
            type: string
          type: object
  headers:
    Deprecation:
      description: >-
        RFC 9745 structured-field Date at which the operation was or will be
        deprecated: `@` followed by Unix seconds, for example `@1767225599`.
      schema:
        pattern: ^@-?[0-9]+$
        type: string
    Idempotent-Replayed:
      description: True when this response was replayed from an earlier attempt.
      schema:
        type: boolean
    Link:
      description: Links related to lifecycle or remediation documentation.
      schema:
        type: string
    RateLimit:
      description: Current rate-limit state.
      schema:
        type: string
    RateLimit-Policy:
      description: Rate-limit policy applied by the gateway.
      schema:
        type: string
    Retry-After:
      description: Delay before retrying, in seconds or as an HTTP date.
      schema:
        type: string
    Sunset:
      description: >-
        RFC 8594 HTTP-date (IMF-fixdate) after which the operation may become
        unavailable, for example `Thu, 31 Dec 2026 23:59:59 GMT`.
      schema:
        pattern: >-
          ^(Mon|Tue|Wed|Thu|Fri|Sat|Sun), [0-9]{2}
          (Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) [0-9]{4}
          [0-9]{2}:[0-9]{2}:[0-9]{2} GMT$
        type: string
    X-Request-ID:
      description: Identifier for this HTTP attempt.
      schema:
        type: string
    X-Trace-ID:
      description: >-
        Trace ID of this request. Sent alongside X-Request-ID when a middleware
        published a trace ID for the request.
      schema:
        pattern: ^(?!0{32}$)[0-9a-f]{32}$
        type: string

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.