All the major OAuth providers. One profile API.Explore the quickstart
Documentation navigation

API reference

The public AnyOAuth authentication contract, generated from the same schema as the SDKs.

On this page

Base URL: https://api.anyoauth.com. Contract version: 0.1.0.

Endpoints

  • POST /v1/login/sessionClean callback login

    Recommended clean-callback flow. Register a fresh 32-byte base64url session key from your backend and retain it in a browser-bound server session. Navigate the browser to authorization_url. The key and client secret must never appear in URLs. AnyOAuth returns to the exact registered callback without query parameters or fragments on success and failure. No automatic retries.

  • POST /v1/login/resultLogin result

    Fetch the clean-callback result from your backend using the original session key, client credentials and callback. Pending reads do not consume the session. A succeeded result carries profile; a failed result carries error. Terminal results are consumed atomically once; expiry, replay and invalid sessions return 400. Verify the initiating browser cookie before calling. No automatic retries after ambiguous failure.

  • GET /authorizeLegacy browser authorization

    Construct this URL locally and navigate the browser. Persist state/verifier in the initiating application session; validate and consume the transaction on callback. Never include a client secret.

  • POST /v1/tokenCode exchange

    Client credentials are in the JSON body, not Basic auth. One-time redemption; no automatic retries after ambiguous failure. Token expires in 900 seconds.

  • GET /v1/profileProfile

    Normalized identity; null fields are legitimate. Use subject, not email, as account key.

  • POST /v1/revokeRevocation

    No body. Syntactically valid bearer tokens are revoked idempotently. Does not terminate the customer app session.

  • GET /api/providersProvider availability

    Deployment-wide status, not project-specific authorization. Browser clients use their backend for this API.

Machine-readable contract

OpenAPI 3.1.1 describes HTTP operations. JSON Schema 2020-12 describes their payloads. These are generated from the canonical public integration contract, not independently maintained reference tables.

Integration model

Google and GitHub sign-in return a single-use handoff code. A confidential backend exchanges it using its project credentials and original PKCE verifier, then fetches a normalized profile. Create your own application session. AnyOAuth is not an OpenID Connect provider and does not return upstream provider tokens.

Start with the Markdown quickstart, callback protection guide or language SDKs. Site-owner session and project management are described in the dashboard guide rather than invented as public SDK operations.