All the major OAuth providers. One profile API.Explore the quickstart
Documentation navigation

Clean callback login

Recommended clean-callback flow. Register a fresh 32-byte base64url session key from your backend and retain it in a browser-bound server session. Navigate the browser to authorization_url. The key and client secret must never appear in URLs. AnyOAuth returns to the exact registered callback without query parameters or fragments on success and failure. No automatic retries.

On this page
POSThttps://api.anyoauth.com/v1/login/session

Authentication: Client ID and secret in JSON; confidential backend only.

Request

Content type: application/json.

FieldTypeRequiredDescription and constraints
client_idstringYesminLength: 1; maxLength: 100
client_secretstringYesminLength: 1; maxLength: 200
session_keystringYespattern: ^[A-Za-z0-9_-]{43}$
provider"google" | "github"Yes
redirect_uristringYesExact registered HTTPS URL or HTTP loopback; no credentials, query or fragment. maxLength: 2048; format: uri; x-validation: redirect
Illustrative JSON request
{
"client_id": "YOUR_CLIENT_ID",
"client_secret": "YOUR_CLIENT_SECRET",
"session_key": "sssssssssssssssssssssssssssssssssssssssssss",
"provider": "google",
"redirect_uri": "https://your-app.example/auth/callback"
}

SDK and HTTP examples

Clean callback login
import { AnyOAuth } from "@anyoauth/node";

const client = new AnyOAuth({
clientId: process.env.ANYOAUTH_CLIENT_ID ?? "YOUR_CLIENT_ID",
clientSecret: process.env.ANYOAUTH_CLIENT_SECRET ?? "YOUR_CLIENT_SECRET",
baseUrl: process.env.ANYOAUTH_API_ORIGIN ?? "https://api.anyoauth.com",
});

const result = await client.createLoginSession({
sessionKey: process.env.ANYOAUTH_SESSION_KEY ?? "sssssssssssssssssssssssssssssssssssssssssss",
provider: "google",
redirectUri: process.env.ANYOAUTH_REDIRECT_URI ?? "https://your-app.example/auth/callback"
});

@anyoauth/node on GitHubConfidential backend SDK

Sample input bindings are illustrative. In a callback handler, take code and transaction values from the validated request and initiating session. Client-only SDKs do not perform confidential exchange.

Response

Success status: 200.

FieldTypeRequiredDescription and constraints
authorization_urlstringYesExact registered HTTPS URL or HTTP loopback; no credentials, query or fragment. maxLength: 2048; format: uri; x-validation: redirect
expires_in600Yes
Illustrative JSON response
{
"authorization_url": "https://api.anyoauth.com/auth/login/aol_lllllllllllllllllllllllllllllllllllllllllll",
"expires_in": 600
}

Errors

Application errors use the shared error model. Infrastructure may return non-JSON responses; SDKs expose structured transport/protocol errors. Do not automatically retry a one-time code exchange.

FieldTypeRequiredDescription and constraints
errorstringYes
messagestringNo
Illustrative error response
{
"error": "request_failed",
"message": "The request could not be completed."
}

Contract source

This page, its field tables and sample inputs derive from OpenAPI version 0.1.0. Download OpenAPI · Download JSON Schema · Request schema · Response schema