GC.AUTH — user access
Authorization code
1. Getting the authorization code
To obtain the code, which can then be exchanged for the correct authorization tokens, redirect the user to:
https://[authorization_server_url]/oauth/authorize?redirect_uri=[redirect_uri]&client_id=[client_id]&response_type=code
- [authorization_server_url] — authorization server address, e.g.
auth.gearcode.eu - [client_id] — identifier of the application (1) the user logs in to. The application must be previously created in GC.AUTH.
- [redirect_uri] — the URL the authorization code is forwarded to. The address must be previously added to the list of allowed addresses (2).
After the user successfully logs in to GC.AUTH, they are redirected to [redirect_uri], with the authorization code attached.
For the application described above, the request and response look as follows:
https://[authorization_server_url]/oauth/authorize?redirect_uri=https%3A%2F%2Fmy.sample.webapp.com%2Fauth-callback&client_id=sample.webapp.fe9d3e203b164c7e8896369673003291&response_type=code
https://my.sample.webapp.com/auth-callback?code=XC3pJl56JP_N8VET3x...pY7h7XCjw
2. Replacing the authorization code with tokens
To exchange the authorization code for tokens, call the HTTP request through a secure channel*:
POST /oauth/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded
code=[code]&grant_type=authorization_code&client_id=[client_id]&client_secret=[client_secret]&resource_id=[client_id]
[client_secret] — secret key of the application; must be stored securely. The key can be obtained in GC.AUTH (1).
If the submitted data is correct, token information is returned in the response:
{
"access_token": "eyJhbGciOi…cP6zb4",
"token_type": "bearer",
"expires_in": 899,
"refresh_token": "ILLu1L5ks…8DZQ"
}
* By secure channel we mean server-to-server communication, with complete omission of the user agent.
Refresh token
The acquired access_token should be periodically refreshed using the refresh_token. To do this, call the HTTP request:
POST /oauth/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded
grant_type=refresh_token&refresh_token=[refresh_token]&client_id=[client_id]&resource_id=[client_id]&client_secret=[client_secret]
If the submitted data is correct, token information is returned in the response:
{
"access_token": "eyJhbGciOi…ZWU1Y2U0",
"token_type": "bearer",
"expires_in": 899,
"refresh_token": "mKhyYrlh…xWIyp"
}