Skip to main content
GET
OAuth authorize

Query Parameters

response_type
string
required
Allowed value: "code"
client_id
string
required
Required string length: 1 - 512
Pattern: ^[^\s\u0000-\u001f\u007f]+$
redirect_uri
string
required
Required string length: 1 - 512
Pattern: ^[^\s\u0000-\u001f\u007f]+$
resource
string
required
Maximum string length: 512
code_challenge
string
required
Pattern: ^[A-Za-z0-9_-]{43}$
code_challenge_method
string
required
Allowed value: "S256"
state
string
Maximum string length: 512
scope
string
Maximum string length: 128

Response

Resolve the client through configuration, persistent registration or its HTTPS metadata document. Validate the requested callback before redirecting. A valid request establishes a signed HttpOnly API-host flow cookie and opens the separate Next.js consent screen. Errors return only to a validated callback with issuer and the supplied state. Unknown clients and unregistered callbacks stay local. S256 PKCE is required; unknown OAuth parameters are ignored.