> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agg.market/llms.txt
> Use this file to discover all available pages before exploring further.

# Start account linking

> Initiates an account-link flow. Authenticated-only. For OAuth providers returns a provider redirect URL and sets an HttpOnly proof cookie that is required at callback time. The same-browser guarantee plus a mode discriminator on the state JWT prevents a phished link URL from attaching a victim's identity to the attacker's principal.



## OpenAPI

````yaml /openapi/openapi.json post /users/me/link-account/start
openapi: 3.0.2
info:
  title: AGG API
  version: 1.0.0
  description: >-
    Prediction market aggregator REST API — authentication, users, venue events,
    venue markets, orderbooks, charts, and execution workflows.
servers:
  - url: https://api.agg.market
    description: Production
  - url: https://api.staging.agg.market
    description: Staging
security: []
paths:
  /users/me/link-account/start:
    post:
      tags:
        - Users
      summary: Start account linking
      description: >-
        Initiates an account-link flow. Authenticated-only. For OAuth providers
        returns a provider redirect URL and sets an HttpOnly proof cookie that
        is required at callback time. The same-browser guarantee plus a mode
        discriminator on the state JWT prevents a phished link URL from
        attaching a victim's identity to the attacker's principal.
      operationId: linkAccountStart
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - provider
              properties:
                provider:
                  type: string
                  enum:
                    - google
                    - twitter
                    - apple
                    - email
                redirectUrl:
                  format: uri
                  type: string
                email:
                  format: email
                  maxLength: 254
                  type: string
      responses:
        '200':
          description: '200'
          content:
            application/json:
              schema:
                type: object
                required:
                  - type
                properties:
                  type:
                    type: string
                    enum:
                      - redirect
                      - magic_link
                  url:
                    type: string
                  success:
                    type: boolean
                    enum:
                      - true
        '400':
          description: '400'
          content:
            application/json:
              schema:
                type: object
                required:
                  - message
                properties:
                  message:
                    type: string
        '401':
          description: '401'
          content:
            application/json:
              schema:
                type: object
                required:
                  - message
                properties:
                  message:
                    type: string
        '403':
          description: '403'
          content:
            application/json:
              schema:
                type: object
                required:
                  - message
                properties:
                  message:
                    type: string
        '429':
          description: '429'
          content:
            application/json:
              schema:
                type: object
                required:
                  - message
                properties:
                  message:
                    type: string
      security:
        - appId: []
          bearerAuth: []
components:
  securitySchemes:
    appId:
      type: apiKey
      in: header
      name: x-app-id
      description: Your application ID. Required for all app-tier and user-tier routes.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT access token returned by POST /auth/verify. Required for user-tier
        routes.

````