v1

latestOpenAPI 3.0.32026-08-0670174396.8 KB
OAuth

Initiate OAuth authorization

OAuth 2.1 authorization endpoint. The client opens the browser at this URL; valid requests are redirected to the frontend consent page where the user approves access.

get/public/v1/oauth/authorize/

Query parameters

client_idstring required

The client_id returned during client registration.

redirect_uristring required

The URI to redirect to after authorization. Must match one of the registered redirect URIs.

response_typestring required

Must be code.

code_challengestring required

PKCE code challenge. Base64url-encoded SHA-256 hash of the code verifier.

code_challenge_methodstring

PKCE method. Only S256 is supported. Defaults to S256 if omitted.

scopestring

Space-separated list of requested scopes. Available value: all. Defaults to the full set of scopes granted during registration if omitted.

statestring

Opaque value to maintain state between the request and the callback. Returned unchanged in the redirect.

resourcestring

RFC 8707 resource indicator — the canonical URI of the API this token will be used against. Forwarded through consent and bound to the issued token.