How the authorization works
The provider sends your browser back to Ferry with a code. Ferry exchanges the code for the access.
You click Connect. Your browser calls POST /api/v1/git/authorize.
The internet does not need to reach your server
GitHub and GitLab never call your server for the authorization. They send your browser back to the dashboard. The dashboard gives the answer to the server. A server on localhost, or on a network that the internet cannot reach, works if it can reach the provider.
The state
The state is a random value. Ferry makes one for each authorization and accepts it one time, for one hour. Ferry refuses an answer that does not have it.
Two round trips on GitHub
On GitHub, the browser makes the round trip two times: one time to create the GitHub App, one time to install it.
If you stop before the end
You can close the tab on GitHub, or refuse on GitLab. Then the connection stays in the list as Not finished. Click Finish connecting to continue from the same step.