Submit OAuth Authorization - Stytch Docs

Documentation Index

Fetch the complete documentation index at: /docs/llms.txt

Use this file to discover all available pages before exploring further.

C#

// POST /v1/b2b/idp/oauth/authorize
const stytch = require('stytch');

const client = new stytch.B2BClient({
  project_id: '${projectId}',
  secret: '${secret}',
});

const params = {
  consent_granted: true,
  scopes: ["openid"],
  client_id: "connected-app-test-d731954d-dab3-4a2b-bdee-07f3ad1be888",
  redirect_uri: "https://app.example/oauth/callback",
  response_type: "code",
};

client.IDP.OAuth.Authorize(params)
  .then(resp => { console.log(resp) })
  .catch(err => { console.log(err) });
// POST /v1/b2b/idp/oauth/authorize
package main

import (
    "context"
    "log"

"github.com/stytchauth/stytch-go/v18/stytch/b2b/b2bstytchapi"
    "github.com/stytchauth/stytch-go/v18/stytch/b2b/idp/oauth"
)

func main() {
    client, err := b2bstytchapi.NewClient(
        "${projectId}",
        "${secret}",
    )
    if err != nil {
        log.Fatalf("error instantiating client: %v", err)
    }

params := &oauth.AuthorizeParams{
        ConsentGranted: true,
        Scopes:         []string{"openid"},
        ClientID:       "connected-app-test-d731954d-dab3-4a2b-bdee-07f3ad1be888",
        RedirectURI:    "https://app.example/oauth/callback",
        ResponseType:   "code",
    }

resp, err := client.IDP.OAuth.Authorize(context.Background(), params)
    if err != nil {
        log.Fatalf("error in method call: %v", err)
    }

log.Println(resp)
}
// POST /v1/b2b/idp/oauth/authorize
package com.example;

import com.stytch.java.b2b.models.idpoauth.AuthorizeRequest;
import com.stytch.java.b2b.StytchB2BClient;
import com.stytch.java.common.StytchResult;

public class Main {
    public static void main(String[] args) {
        StytchB2BClient.configure("${projectId}", "${secret}");

AuthorizeRequest params = new AuthorizeRequest();
        params.setConsentGranted(true);
        params.setScopes(new String("openid"));
        params.setClientId("connected-app-test-d731954d-dab3-4a2b-bdee-07f3ad1be888");
        params.setRedirectUri("https://app.example/oauth/callback");
        params.setResponseType("code");

Object result = StytchB2BClient.getIDP().getOAuth().authorize(params);
        if (result instanceof StytchResult.Success) {
          System.out.println(((StytchResult.Success) result).getValue());
        } else {
          System.out.println(((StytchResult.Error) result).getException());
        }
    }
}
// POST /v1/b2b/idp/oauth/authorize
package com.example

import com.stytch.java.b2b.StytchB2BClient
import com.stytch.java.b2b.models.idpoauth.AuthorizeRequest

fun main() {
    StytchB2BClient.configure(
        projectId = "${projectId}",
        secret = "${secret}",
    )

when (
        val result =
            StytchB2BClient.idp.oauth.authorize(
                AuthorizeRequest(
                    consentGranted = true,
                    scopes = arrayOf("openid"),
                    clientId = "connected-app-test-d731954d-dab3-4a2b-bdee-07f3ad1be888",
                    redirectUri = "https://app.example/oauth/callback",
                    responseType = "code",
                ),
            )
    ) {
        is StytchResult.Success -> println(result.value)
        is StytchResult.Error -> println(result.exception)
    }
}

cURL Example

// POST /v1/b2b/idp/oauth/authorize
curl --request POST \
  --url https://test.stytch.com/v1/b2b/idp/oauth/authorize \
  -u '${projectId}:${secret}' \
  -H 'Content-Type: application/json' \
  -d '{
    "consent_granted": true,
    "scopes": ["openid"],
    "client_id": "connected-app-test-d731954d-dab3-4a2b-bdee-07f3ad1be888",
    "redirect_uri": "https://app.example/oauth/callback",
    "response_type": "code"
  }'

Response Codes

Sample Response

{
  "request_id": "<string>",
  "redirect_uri": "<string>",
  "status_code": 123,
  "authorization_code": "<string>"
}

Authorization

Request Body Fields

Additional Information

If the authorization was successful, the redirect_uri will contain a valid authorization_code embedded as a query parameter. If the authorization was unsuccessful, the redirect_uri will contain an OAuth2.1 error_code. In both cases, redirect the user to the location for the response to be consumed by the Connected App.