Auth API

OAuth 2.0 authentication endpoints. Use these to authorize client applications, obtain consent, and exchange authorization codes for access tokens using the authorization code flow with PKCE.

GET https://api.qonic.com/v1/auth/scopes

List available scopes

Returns all OAuth 2.0 scopes that can be requested during authorization. Each scope grants access to a specific set of API operations. This endpoint is public and does not require authentication.

Response fields

  • Name
    scopes
    Type
    array<object>
    Required
    Optional
    Description
    The list of available OAuth scopes.
    • Name
      name
      Type
      string
      Required
      Optional
      Description
      The scope identifier used in OAuth authorization requests (e.g. "viewer:access").
    • Name
      description
      Type
      string
      Required
      Optional
      Description
      A human-readable description of what this scope grants access to.

GET https://api.qonic.com/v1/auth/authorize

Authorize a client application

Initiates the OAuth 2.0 authorization code flow with PKCE support. Redirects the user to a consent screen if they haven't previously approved the requested scopes. If consent was already granted, immediately issues an authorization code and redirects back to the client.

Query parameters

  • Name
    client_id
    Type
    string
    Required
    Optional
    Description
    The unique identifier of the registered client application.
  • Name
    redirect_uri
    Type
    string
    Required
    Optional
    Description
    The URI to redirect the user to after authorization. Must match one of the registered redirect URIs for the client.
  • Name
    scope
    Type
    string
    Required
    Optional
    Description
    A space-separated list of OAuth scopes to request. Use the list scopes endpoint to see available values.
  • Name
    state
    Type
    string
    Required
    Optional
    Description
    An opaque value used to prevent cross-site request forgery. Returned unchanged in the redirect.
  • Name
    code_challenge
    Type
    string
    Required
    Optional
    Description
    The PKCE code challenge derived from the code verifier. Required when using the authorization code flow with PKCE.
  • Name
    code_challenge_method
    Type
    string
    Required
    Optional
    Description
    The method used to derive the code challenge, typically "S256". Required when code_challenge is provided.

POST https://api.qonic.com/v1/auth/consent

Submits the user's consent decision for the requested scopes. If approved, redirects to the client's redirect_uri with an authorization code. If denied, redirects with an error parameter.

Request body

  • Name
    client_id
    Type
    string
    Required
    Optional
    Description
  • Name
    redirect_uri
    Type
    string
    Required
    Optional
    Description
  • Name
    scope
    Type
    string
    Required
    Optional
    Description
  • Name
    state
    Type
    string
    Required
    Optional
    Description
  • Name
    code_challenge
    Type
    string
    Required
    Optional
    Description
  • Name
    code_challenge_method
    Type
    string
    Required
    Optional
    Description
  • Name
    decision
    Type
    string
    Required
    Optional
    Description

Error responses

  • Name
    400
    Type
    application/problem+json
    Description
    Invalid request parameters or body

    Body: ProblemDetails


POST https://api.qonic.com/v1/auth/token

Exchange authorization code or refresh token for access token

Exchanges an authorization code or refresh token for an access token using the OAuth 2.0 token endpoint. Supports grant_type=authorization_code and grant_type=refresh_token.

Request body

  • Name
    client_id
    Type
    string
    Required
    Optional
    Description
  • Name
    client_secret
    Type
    string
    Required
    Optional
    Description
  • Name
    redirect_uri
    Type
    string
    Required
    Optional
    Description
  • Name
    code
    Type
    string
    Required
    Optional
    Description
  • Name
    code_verifier
    Type
    string
    Required
    Optional
    Description
  • Name
    grant_type
    Type
    string
    Required
    Optional
    Description
  • Name
    refresh_token
    Type
    string
    Required
    Optional
    Description

Response fields

  • Name
    access_token
    Type
    string
    Required
    Optional
    Description
    The access token string used to authenticate API requests.
  • Name
    token_type
    Type
    string
    Required
    Optional
    Description
    The type of token issued (e.g. "Bearer").
  • Name
    scope
    Type
    string
    Required
    Optional
    Description
    The scope of access granted by the token.
  • Name
    refresh_token
    Type
    string
    Required
    Optional
    Description
    The refresh token used to obtain a new access token without re-authenticating.
  • Name
    expires_in
    Type
    integer
    Required
    Optional
    Description
    Lifetime of the access token in seconds.

Error responses

  • Name
    400
    Type
    application/problem+json
    Description
    Invalid request parameters or body

    Body: ProblemDetails