Skip to content

OAuth 2.0 and PKCE

The authorization code + PKCE flow for apps that want to act on behalf of a user.

1 min read 2 sections

Beklio Auth supports the authorization code flow for registered OAuth clients. PKCE is mandatory for public clients (mobile, SPA) and only the S256 method is accepted.

Flow#

  1. Generate a random code_verifier and compute code_challenge = BASE64URL(SHA256(code_verifier)).
  2. Redirect the user to https://accounts.beklio.com/oauth/authorize with response_type=code, client_id, redirect_uri, scope, state, code_challenge and code_challenge_method=S256.
  3. Once the user approves, they are sent back to your redirect_uri with code and state. Always verify the state value.
  4. Exchange the code for tokens.
token-exchange.sh
curl -X POST "https://api.beklio.com/oauth/token" \
  -H "Content-Type: application/json" \
  -d '{
    "grant_type": "authorization_code",
    "client_id": "YOUR_CLIENT_ID",
    "code": "AUTHORIZATION_CODE",
    "redirect_uri": "https://app.example.com/callback",
    "code_verifier": "YOUR_CODE_VERIFIER"
  }'

The response contains access_token, token_type: "Bearer", expires_in and, if the client is allowed, a refresh_token.

Rules#

  • redirect_uri must match one of the client's registered addresses exactly.
  • An authorization code is single-use and short-lived; a second exchange with the same code is rejected.
  • Use grant_type: "refresh_token" to refresh.

Is something missing or wrong? Write to the support team; including the X-Request-Id value from the response speeds up the fix.