Where Smokeball sends the browser back after the user authorizes; it needs no sign-in, the state value ties it to the connect request. Saves the connection and redirects (302) to the portal with smokeball=connected. Returns 401 when code or state is missing and 403 while the Smokeball integration is turned off.
GET
/legal/smokeball/callback
curl \
--request GET 'http://api.example.com/legal/smokeball/callback?code=string&state=string' \
--header "Authorization: Bearer $ACCESS_TOKEN"