All the major OAuth providers. One profile API.Explore the quickstart
Documentation navigation

Legacy browser authorization

Construct this URL locally and navigate the browser. Persist state/verifier in the initiating application session; validate and consume the transaction on callback. Never include a client secret.

On this page
GEThttps://api.anyoauth.com/authorize

Authentication: Browser navigation with public client ID, state and PKCE.

Request

Construct this URL locally and navigate the initiating browser. Keep the saved verifier on the application's backend or protected initiating session.

FieldTypeRequiredDescription and constraints
client_idstringYesminLength: 1
provider"google" | "github"Yes
redirect_uristringYesExact registered HTTPS URL or HTTP loopback; no credentials, query or fragment. maxLength: 2048; format: uri; x-validation: redirect
statestringYesminLength: 16; maxLength: 512
code_challengestringYespattern: ^[A-Za-z0-9_-]{43}$
code_challenge_method"S256"Yes
response_type"code"Yes

SDK and HTTP examples

Legacy browser authorization
import { AnyOAuth } from "@anyoauth/node";

const client = new AnyOAuth({
clientId: process.env.ANYOAUTH_CLIENT_ID ?? "YOUR_CLIENT_ID",
clientSecret: process.env.ANYOAUTH_CLIENT_SECRET ?? "YOUR_CLIENT_SECRET",
baseUrl: process.env.ANYOAUTH_API_ORIGIN ?? "https://api.anyoauth.com",
});

const transaction = await client.createTransaction();
// Persist this transaction in the initiating session before navigation.
const authorizationUrl = client.authorizationUrl({
provider: "google",
redirectUri: process.env.ANYOAUTH_REDIRECT_URI ?? "https://your-app.example/auth/callback",
state: transaction.state,
codeChallenge: transaction.codeChallenge
});

@anyoauth/node on GitHubConfidential backend SDK

Sample input bindings are illustrative. In a callback handler, take code and transaction values from the validated request and initiating session. Client-only SDKs do not perform confidential exchange.

Response

Success status: 302.

Browser redirect. The Location header points to the configured provider.

Errors

Application errors use the shared error model. Infrastructure may return non-JSON responses; SDKs expose structured transport/protocol errors. Do not automatically retry a one-time code exchange.

FieldTypeRequiredDescription and constraints
errorstringYes
messagestringNo
Illustrative error response
{
"error": "request_failed",
"message": "The request could not be completed."
}

Contract source

This page, its field tables and sample inputs derive from OpenAPI version 0.1.0. Download OpenAPI · Download JSON Schema