API reference
The public AnyOAuth authentication contract, generated from the same schema as the SDKs.
On this page
Base URL: https://api.anyoauth.com. Contract version: 0.1.0.
Endpoints
POST /v1/login/sessionClean callback loginRecommended clean-callback flow. Register a fresh 32-byte base64url session key from your backend and retain it in a browser-bound server session. Navigate the browser to authorization_url. The key and client secret must never appear in URLs. AnyOAuth returns to the exact registered callback without query parameters or fragments on success and failure. No automatic retries.
POST /v1/login/resultLogin resultFetch the clean-callback result from your backend using the original session key, client credentials and callback. Pending reads do not consume the session. A succeeded result carries profile; a failed result carries error. Terminal results are consumed atomically once; expiry, replay and invalid sessions return 400. Verify the initiating browser cookie before calling. No automatic retries after ambiguous failure.
GET /authorizeLegacy browser authorizationConstruct this URL locally and navigate the browser. Persist state/verifier in the initiating application session; validate and consume the transaction on callback. Never include a client secret.
POST /v1/tokenCode exchangeClient credentials are in the JSON body, not Basic auth. One-time redemption; no automatic retries after ambiguous failure. Token expires in 900 seconds.
GET /v1/profileProfileNormalized identity; null fields are legitimate. Use subject, not email, as account key.
POST /v1/revokeRevocationNo body. Syntactically valid bearer tokens are revoked idempotently. Does not terminate the customer app session.
GET /api/providersProvider availabilityDeployment-wide status, not project-specific authorization. Browser clients use their backend for this API.
Machine-readable contract
OpenAPI 3.1.1 describes HTTP operations. JSON Schema 2020-12 describes their payloads. These are generated from the canonical public integration contract, not independently maintained reference tables.
Integration model
Google and GitHub sign-in return a single-use handoff code. A confidential backend exchanges it using its project credentials and original PKCE verifier, then fetches a normalized profile. Create your own application session. AnyOAuth is not an OpenID Connect provider and does not return upstream provider tokens.
Start with the Markdown quickstart, callback protection guide or language SDKs. Site-owner session and project management are described in the dashboard guide rather than invented as public SDK operations.