Get OAuth2 Login Request
GET
/appid-{appId}/recipe/oauth/auth/requests/loginAuthorization
api-keyAPI key · headerrequiredThe core service API token. If you are using a self-hosted core service and you have not generated a token, you can omit the header.
Query parameters
loginChallengestringrequiredHeader parameters
cdi-versionstringX.Y of the X.Y.Z CDI version.
Responses
200OAuth2 Login Result
One of:
object
statusstatusOKAllowed:
OKchallengestringclientoauthClientShow propertiesHide properties
clientIdstringclientNamestringclientSecretstringredirectUrisstring[]grantTypesstring[]responseTypesstring[]scopestringaudiencestring[]policyUristringallowedCorsOriginsstring[]tosUristringclientUristringlogoUristringtokenEndpointAuthMethodstringcreatedAtstring<date-time>updatedAtstring<date-time>postLogoutRedirectUrisstring[]metadataobjectauthorizationCodeGrantAccessTokenLifespanstring | nullauthorizationCodeGrantIdTokenLifespanstring | nullauthorizationCodeGrantRefreshTokenLifespanstring | nullclientCredentialsGrantAccessTokenLifespanstring | nullimplicitGrantAccessTokenLifespanstring | nullimplicitGrantIdTokenLifespanstring | nullrefreshTokenGrantIdTokenLifespanstring | nullrefreshTokenGrantAccessTokenLifespanstring | nullrefreshTokenGrantRefreshTokenLifespanstring | nullenableRefreshTokenRotationbooleanoidcContextobjectShow propertiesHide properties
acrValuesstring[]displaystringidTokenHintClaimsobjectloginHintstringuiLocalesstring[]requestUrlstringrequestedAccessTokenAudiencestring[]requestedScopestring[]sessionIdstringskipbooleansubjectstringoauthError
statusstringrequiredAllowed:
OAUTH_ERRORerrorstringrequirederrorDescriptionstringrequiredstatusCodeintegerrequired400error code 400
string401error code 401
string402error code 402
string404error code 404
string500error code 500
stringTry it
Server
Authorization
Parameters
Request
curl -X GET "/appid-{appId}/recipe/oauth/auth/requests/login?loginChallenge=1234567890" \
-H "api-key: YOUR_API_KEY"const response = await fetch("/appid-{appId}/recipe/oauth/auth/requests/login?loginChallenge=1234567890", {
method: "GET",
headers: {
"api-key": "YOUR_API_KEY"
}
});import requests
response = requests.get(
"/appid-{appId}/recipe/oauth/auth/requests/login?loginChallenge=1234567890",
headers={
"api-key": "YOUR_API_KEY"
},
)Response
{
"status": "OK",
"challenge": "string",
"client": {
"clientId": "stcl_c6dd9189-33b8-4ec0-8aea-a0ffdaf75fcb",
"clientName": "Hello",
"clientSecret": "T98n1YIMWqr4wOM.~bV4HOPFmO",
"redirectUris": [
"http://localhost:3000/auth/callback/ory"
],
"grantTypes": [
"authorization_code",
"refresh_token"
],
"responseTypes": [
"code",
"id_token"
],
"scope": "offline_access openid email",
"audience": [],
"policyUri": "",
"allowedCorsOrigins": [],
"tosUri": "",
"clientUri": "",
"logoUri": "",
"tokenEndpointAuthMethod": "client_secret_post",
"createdAt": "2025-02-24T08:14:40Z",
"updatedAt": "2025-02-24T08:14:40.362463Z",
"postLogoutRedirectUris": [
"http://localhost:3000"
],
"metadata": {},
"authorizationCodeGrantAccessTokenLifespan": "1h0m0s",
"authorizationCodeGrantIdTokenLifespan": "1h0m0s",
"authorizationCodeGrantRefreshTokenLifespan": "1h0m0s",
"clientCredentialsGrantAccessTokenLifespan": "1h0m0s",
"implicitGrantAccessTokenLifespan": "1h0m0s",
"implicitGrantIdTokenLifespan": "1h0m0s",
"refreshTokenGrantIdTokenLifespan": "1h0m0s",
"refreshTokenGrantAccessTokenLifespan": "1h0m0s",
"refreshTokenGrantRefreshTokenLifespan": "1h0m0s",
"enableRefreshTokenRotation": false
},
"oidcContext": {
"acrValues": [
"string"
],
"display": "string",
"idTokenHintClaims": {},
"loginHint": "string",
"uiLocales": [
"string"
],
"requestUrl": "string",
"requestedAccessTokenAudience": [
"string"
],
"requestedScope": [
"string"
],
"sessionId": "string",
"skip": true,
"subject": "string"
}
}"string""Invalid API key""License Error""Not Found""Internal Error"