Auth API
OAuth 2.0 authentication endpoints. Use these to authorize client applications, obtain consent, and exchange authorization codes for access tokens using the authorization code flow with PKCE.
List available scopes
Returns all OAuth 2.0 scopes that can be requested during authorization. Each scope grants access to a specific set of API operations. This endpoint is public and does not require authentication.
Response fields
-
- Name
-
scopes - Type
- array<object>
- Required
- Optional
- Description
- The list of available OAuth scopes.
-
-
- Name
-
name - Type
- string
- Required
- Optional
- Description
- The scope identifier used in OAuth authorization requests (e.g. "viewer:access").
-
- Name
-
description - Type
- string
- Required
- Optional
- Description
- A human-readable description of what this scope grants access to.
-
Authorize a client application
Initiates the OAuth 2.0 authorization code flow with PKCE support. Redirects the user to a consent screen if they haven't previously approved the requested scopes. If consent was already granted, immediately issues an authorization code and redirects back to the client.
Query parameters
-
- Name
-
client_id - Type
- string
- Required
- Optional
- Description
- The unique identifier of the registered client application.
-
- Name
-
redirect_uri - Type
- string
- Required
- Optional
- Description
- The URI to redirect the user to after authorization. Must match one of the registered redirect URIs for the client.
-
- Name
-
scope - Type
- string
- Required
- Optional
- Description
- A space-separated list of OAuth scopes to request. Use the list scopes endpoint to see available values.
-
- Name
-
state - Type
- string
- Required
- Optional
- Description
- An opaque value used to prevent cross-site request forgery. Returned unchanged in the redirect.
-
- Name
-
code_challenge - Type
- string
- Required
- Optional
- Description
- The PKCE code challenge derived from the code verifier. Required when using the authorization code flow with PKCE.
-
- Name
-
code_challenge_method - Type
- string
- Required
- Optional
- Description
- The method used to derive the code challenge, typically "S256". Required when code_challenge is provided.
Submit user consent decision
Submits the user's consent decision for the requested scopes. If approved, redirects to the client's redirect_uri with an authorization code. If denied, redirects with an error parameter.
Request body
-
- Name
-
client_id - Type
- string
- Required
- Optional
- Description
-
- Name
-
redirect_uri - Type
- string
- Required
- Optional
- Description
-
- Name
-
scope - Type
- string
- Required
- Optional
- Description
-
- Name
-
state - Type
- string
- Required
- Optional
- Description
-
- Name
-
code_challenge - Type
- string
- Required
- Optional
- Description
-
- Name
-
code_challenge_method - Type
- string
- Required
- Optional
- Description
-
- Name
-
decision - Type
- string
- Required
- Optional
- Description
Error responses
-
- Name
-
400 - Type
- application/problem+json
- Description
- Invalid request parameters or body
Body:
ProblemDetails
Exchange authorization code or refresh token for access token
Exchanges an authorization code or refresh token for an access token using the OAuth 2.0 token endpoint. Supports grant_type=authorization_code and grant_type=refresh_token.
Request body
-
- Name
-
client_id - Type
- string
- Required
- Optional
- Description
-
- Name
-
client_secret - Type
- string
- Required
- Optional
- Description
-
- Name
-
redirect_uri - Type
- string
- Required
- Optional
- Description
-
- Name
-
code - Type
- string
- Required
- Optional
- Description
-
- Name
-
code_verifier - Type
- string
- Required
- Optional
- Description
-
- Name
-
grant_type - Type
- string
- Required
- Optional
- Description
-
- Name
-
refresh_token - Type
- string
- Required
- Optional
- Description
Response fields
-
- Name
-
access_token - Type
- string
- Required
- Optional
- Description
- The access token string used to authenticate API requests.
-
- Name
-
token_type - Type
- string
- Required
- Optional
- Description
- The type of token issued (e.g. "Bearer").
-
- Name
-
scope - Type
- string
- Required
- Optional
- Description
- The scope of access granted by the token.
-
- Name
-
refresh_token - Type
- string
- Required
- Optional
- Description
- The refresh token used to obtain a new access token without re-authenticating.
-
- Name
-
expires_in - Type
- integer
- Required
- Optional
- Description
- Lifetime of the access token in seconds.
Error responses
-
- Name
-
400 - Type
- application/problem+json
- Description
- Invalid request parameters or body
Body:
ProblemDetails