OAuth 2.0 and PKCE
The authorization code + PKCE flow for apps that want to act on behalf of a user.
1 min read 2 sections
Beklio Auth supports the authorization code flow for registered OAuth clients. PKCE is mandatory for public clients (mobile, SPA) and only the S256 method is accepted.
Flow#
- Generate a random
code_verifierand computecode_challenge = BASE64URL(SHA256(code_verifier)). - Redirect the user to
https://accounts.beklio.com/oauth/authorizewithresponse_type=code,client_id,redirect_uri,scope,state,code_challengeandcode_challenge_method=S256. - Once the user approves, they are sent back to your
redirect_uriwithcodeandstate. Always verify thestatevalue. - Exchange the code for tokens.
token-exchange.sh
curl -X POST "https://api.beklio.com/oauth/token" \
-H "Content-Type: application/json" \
-d '{
"grant_type": "authorization_code",
"client_id": "YOUR_CLIENT_ID",
"code": "AUTHORIZATION_CODE",
"redirect_uri": "https://app.example.com/callback",
"code_verifier": "YOUR_CODE_VERIFIER"
}'The response contains access_token, token_type: "Bearer", expires_in and, if the client is allowed, a refresh_token.
Rules#
redirect_urimust match one of the client's registered addresses exactly.- An authorization code is single-use and short-lived; a second exchange with the same code is rejected.
- Use
grant_type: "refresh_token"to refresh.
Is something missing or wrong? Write to the support team; including the X-Request-Id value from the response speeds up the fix.