GC.AUTH — user access

Authorization code

1. Getting the authorization code

To obtain the code, which can then be exchanged for the correct authorization tokens, redirect the user to:

https://[authorization_server_url]/oauth/authorize?redirect_uri=[redirect_uri]&client_id=[client_id]&response_type=code
  • [authorization_server_url] — authorization server address, e.g. auth.gearcode.eu
  • [client_id] — identifier of the application (1) the user logs in to. The application must be previously created in GC.AUTH.
  • [redirect_uri] — the URL the authorization code is forwarded to. The address must be previously added to the list of allowed addresses (2).

After the user successfully logs in to GC.AUTH, they are redirected to [redirect_uri], with the authorization code attached.

For the application described above, the request and response look as follows:

https://[authorization_server_url]/oauth/authorize?redirect_uri=https%3A%2F%2Fmy.sample.webapp.com%2Fauth-callback&client_id=sample.webapp.fe9d3e203b164c7e8896369673003291&response_type=code

https://my.sample.webapp.com/auth-callback?code=XC3pJl56JP_N8VET3x...pY7h7XCjw

2. Replacing the authorization code with tokens

To exchange the authorization code for tokens, call the HTTP request through a secure channel*:

POST /oauth/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded

code=[code]&grant_type=authorization_code&client_id=[client_id]&client_secret=[client_secret]&resource_id=[client_id]

[client_secret] — secret key of the application; must be stored securely. The key can be obtained in GC.AUTH (1).

If the submitted data is correct, token information is returned in the response:

{
  "access_token": "eyJhbGciOi…cP6zb4",
  "token_type": "bearer",
  "expires_in": 899,
  "refresh_token": "ILLu1L5ks…8DZQ"
}

* By secure channel we mean server-to-server communication, with complete omission of the user agent.

Refresh token

The acquired access_token should be periodically refreshed using the refresh_token. To do this, call the HTTP request:

POST /oauth/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded

grant_type=refresh_token&refresh_token=[refresh_token]&client_id=[client_id]&resource_id=[client_id]&client_secret=[client_secret]

If the submitted data is correct, token information is returned in the response:

{
  "access_token": "eyJhbGciOi…ZWU1Y2U0",
  "token_type": "bearer",
  "expires_in": 899,
  "refresh_token": "mKhyYrlh…xWIyp"
}