API referenceKeys and access
Authorize a third-party app
Consent step of Sign in with GridRouter (OAuth PKCE, S256): a signed-in member approves an app and gets a one-time code (10 minutes) to redirect back with.
Authorization
bearer AuthorizationBearer <token>
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
curl -X POST "https://example.com/v1/auth/codes" \ -H "Content-Type: application/json" \ -d '{ "code_challenge": "string" }'{ "object": "auth_code", "code": "string", "redirect_url": "string", "expires_at": "2019-08-24T14:15:22Z"}Register an app PUT
Name an attributed app and opt it in (or out) of the public rankings and showcase. A domain-style id must match its URL; another org's public id is refused.
Exchange an app code for a key POST
Final step of Sign in with GridRouter: exchange the one-time code and its PKCE code_verifier for a user-controlled key with call/run scopes and any credit limit the user set.