Legacy browser authorization
Construct this URL locally and navigate the browser. Persist state/verifier in the initiating application session; validate and consume the transaction on callback. Never include a client secret.
On this page
https://api.anyoauth.com/authorizeAuthentication: Browser navigation with public client ID, state and PKCE.
Request
Construct this URL locally and navigate the initiating browser. Keep the saved verifier on the application's backend or protected initiating session.
| Field | Type | Required | Description and constraints |
|---|---|---|---|
client_id | string | Yes | minLength: 1 |
provider | "google" | "github" | Yes | |
redirect_uri | string | Yes | Exact registered HTTPS URL or HTTP loopback; no credentials, query or fragment. maxLength: 2048; format: uri; x-validation: redirect |
state | string | Yes | minLength: 16; maxLength: 512 |
code_challenge | string | Yes | pattern: ^[A-Za-z0-9_-]{43}$ |
code_challenge_method | "S256" | Yes | |
response_type | "code" | Yes |
SDK and HTTP examples
import { AnyOAuth } from "@anyoauth/node";
const client = new AnyOAuth({
clientId: process.env.ANYOAUTH_CLIENT_ID ?? "YOUR_CLIENT_ID",
clientSecret: process.env.ANYOAUTH_CLIENT_SECRET ?? "YOUR_CLIENT_SECRET",
baseUrl: process.env.ANYOAUTH_API_ORIGIN ?? "https://api.anyoauth.com",
});
const transaction = await client.createTransaction();
// Persist this transaction in the initiating session before navigation.
const authorizationUrl = client.authorizationUrl({
provider: "google",
redirectUri: process.env.ANYOAUTH_REDIRECT_URI ?? "https://your-app.example/auth/callback",
state: transaction.state,
codeChallenge: transaction.codeChallenge
});
@anyoauth/node on GitHubConfidential backend SDK
// Supply these public settings from your app configuration.
const settings = globalThis.ANYOAUTH_SETTINGS ?? {};
import { AnyOAuth } from "@anyoauth/client";
const client = new AnyOAuth({
clientId: settings.ANYOAUTH_CLIENT_ID ?? "YOUR_CLIENT_ID",
baseUrl: settings.ANYOAUTH_API_ORIGIN ?? "https://api.anyoauth.com",
});
const transaction = await client.createTransaction();
// Persist this transaction in the initiating session before navigation.
const authorizationUrl = client.authorizationUrl({
provider: "google",
redirectUri: settings.ANYOAUTH_REDIRECT_URI ?? "https://your-app.example/auth/callback",
state: transaction.state,
codeChallenge: transaction.codeChallenge
});
@anyoauth/client on GitHubClient helpers · backend exchange required
// Supply these public settings from your app configuration.
const settings = globalThis.ANYOAUTH_SETTINGS ?? {};
import { AnyOAuth } from "@anyoauth/expo/native";
import * as Crypto from 'expo-crypto';
const client = new AnyOAuth({
crypto: Crypto,
clientId: settings.ANYOAUTH_CLIENT_ID ?? "YOUR_CLIENT_ID",
baseUrl: settings.ANYOAUTH_API_ORIGIN ?? "https://api.anyoauth.com",
});
const transaction = await client.createTransaction();
// Persist this transaction in the initiating session before navigation.
const authorizationUrl = client.authorizationUrl({
provider: "google",
redirectUri: settings.ANYOAUTH_REDIRECT_URI ?? "https://your-app.example/auth/callback",
state: transaction.state,
codeChallenge: transaction.codeChallenge
});
@anyoauth/expo on GitHubClient helpers · backend exchange required
import os
from anyoauth import Client
client = Client(os.getenv("ANYOAUTH_CLIENT_ID", "YOUR_CLIENT_ID"), os.getenv("ANYOAUTH_CLIENT_SECRET", "YOUR_CLIENT_SECRET"), os.getenv("ANYOAUTH_API_ORIGIN", "https://api.anyoauth.com"))
transaction = client.create_transaction()
# Persist the transaction in the initiating session.
authorizationUrl = client.authorization_url({"provider": "google", "redirectUri": os.getenv("ANYOAUTH_REDIRECT_URI", "https://your-app.example/auth/callback"), "state": transaction["state"], "codeChallenge": transaction["codeChallenge"]})
anyoauth-sdk on GitHubConfidential backend SDK
package main
import (
"os"
anyoauth "github.com/AnyOAuth/anyoauth-go"
)
func env(key, fallback string) string { if v := os.Getenv(key); v != "" { return v }; return fallback }
func main() {
client, err := anyoauth.NewClient(env("ANYOAUTH_API_ORIGIN", "https://api.anyoauth.com"), env("ANYOAUTH_CLIENT_ID", "YOUR_CLIENT_ID"), env("ANYOAUTH_CLIENT_SECRET", "YOUR_CLIENT_SECRET"))
if err != nil { panic(err) }
transaction, err := anyoauth.CreateTransaction()
if err != nil { panic(err) }
// Persist the transaction in the initiating session.
authorizationUrl, err := client.AuthorizationURL(map[string]any{"provider": "google", "redirectUri": env("ANYOAUTH_REDIRECT_URI", "https://your-app.example/auth/callback"), "state": transaction["state"].(string), "codeChallenge": transaction["codeChallenge"].(string)})
if err != nil { panic(err) }
_ = authorizationUrl
}
github.com/AnyOAuth/anyoauth-go on GitHubConfidential backend SDK
<?php
require 'vendor/autoload.php';
$client = new \AnyOAuth\Client((getenv("ANYOAUTH_CLIENT_ID") ?: "YOUR_CLIENT_ID"), (getenv("ANYOAUTH_CLIENT_SECRET") ?: "YOUR_CLIENT_SECRET"), (getenv("ANYOAUTH_API_ORIGIN") ?: "https://api.anyoauth.com"));
$transaction = $client->createTransaction();
// Persist the transaction in the initiating session.
$authorizationUrl = $client->authorizationUrl(["provider" => "google", "redirectUri" => (getenv("ANYOAUTH_REDIRECT_URI") ?: "https://your-app.example/auth/callback"), "state" => $transaction->state, "codeChallenge" => $transaction->codeChallenge]);
anyoauth/anyoauth on GitHubConfidential backend SDK
import com.anyoauth.AnyOAuth;
import com.google.gson.*;
public class Example {
static String env(String key, String fallback) { String value = System.getenv(key); return value == null ? fallback : value; }
public static void main(String[] args) {
AnyOAuth client = new AnyOAuth(env("ANYOAUTH_API_ORIGIN", "https://api.anyoauth.com"), env("ANYOAUTH_CLIENT_ID", "YOUR_CLIENT_ID"), env("ANYOAUTH_CLIENT_SECRET", "YOUR_CLIENT_SECRET"));
JsonObject transaction = AnyOAuth.createTransaction();
// Persist the transaction in the initiating session.
JsonObject params = new JsonObject();
params.addProperty("provider", "google");
params.addProperty("redirectUri", env("ANYOAUTH_REDIRECT_URI", "https://your-app.example/auth/callback"));
params.addProperty("state", transaction.get("state").getAsString());
params.addProperty("codeChallenge", transaction.get("codeChallenge").getAsString());
var authorizationUrl = client.authorizationUrl(params);
}
}
com.anyoauth:anyoauth on GitHubConfidential backend SDK
require "anyoauth"
client = AnyOAuth::Client.new(ENV.fetch("ANYOAUTH_CLIENT_ID", "YOUR_CLIENT_ID"), ENV.fetch("ANYOAUTH_CLIENT_SECRET", "YOUR_CLIENT_SECRET"), ENV.fetch("ANYOAUTH_API_ORIGIN", "https://api.anyoauth.com"))
transaction = client.create_transaction
# Persist the transaction in the initiating session.
authorizationUrl = client.authorization_url({"provider" => "google", "redirectUri" => ENV.fetch("ANYOAUTH_REDIRECT_URI", "https://your-app.example/auth/callback"), "state" => transaction["state"], "codeChallenge" => transaction["codeChallenge"]})
anyoauth-sdk on GitHubConfidential backend SDK
using System;
using System.Text.Json.Nodes;
using AnyOAuth;
using var client = new Client(Environment.GetEnvironmentVariable("ANYOAUTH_API_ORIGIN") ?? "https://api.anyoauth.com", Environment.GetEnvironmentVariable("ANYOAUTH_CLIENT_ID") ?? "YOUR_CLIENT_ID", Environment.GetEnvironmentVariable("ANYOAUTH_CLIENT_SECRET") ?? "YOUR_CLIENT_SECRET");
var transaction = Client.CreateTransaction();
// Persist the transaction in the initiating session.
var authorizationUrl = client.AuthorizationUrl(new JsonObject { ["provider"] = "google", ["redirectUri"] = Environment.GetEnvironmentVariable("ANYOAUTH_REDIRECT_URI") ?? "https://your-app.example/auth/callback", ["state"] = transaction["state"]!.GetValue<string>(), ["codeChallenge"] = transaction["codeChallenge"]!.GetValue<string>() });
AnyOAuth.SDK on GitHubConfidential backend SDK
use anyoauth_sdk::*;
use serde_json::json;
fn env(key: &str, fallback: &str) -> String { std::env::var(key).unwrap_or_else(|_| fallback.to_owned()) }
fn main() -> Result<(), Box<dyn std::error::Error>> {
let client = Client::new(&env("ANYOAUTH_API_ORIGIN", "https://api.anyoauth.com"), &env("ANYOAUTH_CLIENT_ID", "YOUR_CLIENT_ID"), &env("ANYOAUTH_CLIENT_SECRET", "YOUR_CLIENT_SECRET"))?;
let transaction = create_transaction()?;
// Persist the transaction in the initiating session.
let authorizationUrl = client.authorization_url(&json!({"provider": "google", "redirectUri": env("ANYOAUTH_REDIRECT_URI", "https://your-app.example/auth/callback"), "state": transaction["state"].as_str().unwrap(), "codeChallenge": transaction["codeChallenge"].as_str().unwrap()}))?;
let _ = &authorizationUrl;
Ok(())
}
anyoauth-sdk on GitHubConfidential backend SDK
client = AnyOAuth.new((System.get_env("ANYOAUTH_CLIENT_ID") || "YOUR_CLIENT_ID"), (System.get_env("ANYOAUTH_CLIENT_SECRET") || "YOUR_CLIENT_SECRET"), (System.get_env("ANYOAUTH_API_ORIGIN") || "https://api.anyoauth.com"))
transaction = AnyOAuth.create_transaction(client)
# Persist the transaction in the initiating session.
authorizationUrl = AnyOAuth.authorization_url(client, %{"provider" => "google", "redirectUri" => (System.get_env("ANYOAUTH_REDIRECT_URI") || "https://your-app.example/auth/callback"), "state" => transaction["state"], "codeChallenge" => transaction["codeChallenge"]})
anyoauth_sdk on GitHubConfidential backend SDK
import Foundation
import AnyOAuth
func env(_ key: String, _ fallback: String) -> String { ProcessInfo.processInfo.environment[key] ?? fallback }
let client = try AnyOAuth(clientId: env("ANYOAUTH_CLIENT_ID", "YOUR_CLIENT_ID"), baseUrl: env("ANYOAUTH_API_ORIGIN", "https://api.anyoauth.com"))
let transaction = try client.createTransaction()
// Persist the transaction in the initiating session.
let authorizationUrl = try client.authorizationUrl(provider: "google", redirectUri: env("ANYOAUTH_REDIRECT_URI", "https://your-app.example/auth/callback"), state: transaction.state, codeChallenge: transaction.codeChallenge)
AnyOAuth on GitHubClient helpers · backend exchange required
import com.anyoauth.*
fun env(key: String, fallback: String): String = System.getenv(key) ?: fallback
fun main() {
val client = AnyOAuth(env("ANYOAUTH_CLIENT_ID", "YOUR_CLIENT_ID"), env("ANYOAUTH_API_ORIGIN", "https://api.anyoauth.com"))
val transaction = client.createTransaction()
// Persist the transaction in the initiating session.
val authorizationUrl = client.authorizationUrl(provider = "google", redirectUri = env("ANYOAUTH_REDIRECT_URI", "https://your-app.example/auth/callback"), state = transaction.state, codeChallenge = transaction.codeChallenge)
}
com.anyoauth:anyoauth-client on GitHubClient helpers · backend exchange required
import 'dart:io';
import 'package:anyoauth_client/anyoauth_client.dart';
String env(String key, String fallback) => Platform.environment[key] ?? fallback;
void main() {
final client = AnyOAuth(clientId: env("ANYOAUTH_CLIENT_ID", "YOUR_CLIENT_ID"), baseUrl: env("ANYOAUTH_API_ORIGIN", "https://api.anyoauth.com"));
final transaction = client.createTransaction();
// Persist the transaction in the initiating session.
final authorizationUrl = client.authorizationUrl(provider: "google", redirectUri: env("ANYOAUTH_REDIRECT_URI", "https://your-app.example/auth/callback"), state: transaction.state, codeChallenge: transaction.codeChallenge);
}
anyoauth_client on GitHubClient helpers · backend exchange required
# Open this URL in the initiating browser after saving its state/verifier.
# This is a browser redirect, not a background token exchange.
https://api.anyoauth.com/authorize?client_id=YOUR_CLIENT_ID&provider=google&redirect_uri=https%3A%2F%2Fyour-app.example%2Fauth%2Fcallback&state=YOUR_BROWSER_BOUND_STATE&code_challenge=E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM&code_challenge_method=S256&response_type=code
HTTP reference · keep credentials on your backend
Sample input bindings are illustrative. In a callback handler, take code and transaction values from the validated request and initiating session. Client-only SDKs do not perform confidential exchange.
Response
Success status: 302.
Browser redirect. The Location header points to the configured provider.
Errors
Application errors use the shared error model. Infrastructure may return non-JSON responses; SDKs expose structured transport/protocol errors. Do not automatically retry a one-time code exchange.
| Field | Type | Required | Description and constraints |
|---|---|---|---|
error | string | Yes | |
message | string | No |
{
"error": "request_failed",
"message": "The request could not be completed."
}Contract source
This page, its field tables and sample inputs derive from OpenAPI version 0.1.0. Download OpenAPI · Download JSON Schema