O Auth Authorise
Start the OAuth 2.0 Authorization Code flow with PKCE. This endpoint accepts either a browser session (`storyden-session` cookie) or a personal access key (`Authorization: Bearer <key>`), letting a headless script drive the whole flow without ever loading the web frontend. If neither credential is present, Storyden redirects to a login URL instead of returning a protocol redirect to the client application; this defaults to the frontend login route and can be changed with `OAUTH_AUTHORISATION_LOGIN_URL`. Unlike many OAuth servers, Storyden does not render a consent page from this API endpoint. A valid request creates a short-lived pending authorisation request and redirects to the configured authorisation-code consent URL. A script can parse `request_id` out of that redirect's query string and drive `/oauth/authorize/consent` directly instead of following the redirect in a browser. Custom frontends can change this URL with `OAUTH_AUTHORISATION_CODE_CONSENT_URL`. The `scope` parameter follows OAuth 2.0 and is optional. Empty or omitted scope means no requested scopes. Storyden permission scopes are granted only when allowed by the client and by the signed-in account's current permissions.
/oauth/authorizeStart the OAuth 2.0 Authorization Code flow with PKCE.
This endpoint accepts either a browser session (storyden-session
cookie) or a personal access key (Authorization: Bearer <key>),
letting a headless script drive the whole flow without ever loading
the web frontend. If neither credential is present, Storyden redirects
to a login URL instead of returning a protocol redirect to the client
application; this defaults to the frontend login route and can be
changed with OAUTH_AUTHORISATION_LOGIN_URL.
Unlike many OAuth servers, Storyden does not render a consent page from
this API endpoint. A valid request creates a short-lived pending
authorisation request and redirects to the configured
authorisation-code consent URL. A script can parse request_id out of
that redirect's query string and drive /oauth/authorize/consent
directly instead of following the redirect in a browser. Custom
frontends can change this URL with OAUTH_AUTHORISATION_CODE_CONSENT_URL.
The scope parameter follows OAuth 2.0 and is optional. Empty or
omitted scope means no requested scopes. Storyden permission scopes are
granted only when allowed by the client and by the signed-in account's
current permissions.
In: cookie
Query Parameters
OAuth response type. Storyden currently supports authorisation code.
OAuth client identifier.
Registered redirect URI for the OAuth client.
Space-separated OAuth scopes requested by the client.
Client-provided opaque state returned to the redirect URI.
OpenID Connect nonce. When provided, it is returned unmodified as the
nonce claim in the issued ID token (OIDC Core §3.1.2).
PKCE code challenge.
PKCE code challenge method.
Response Body
text/html
application/json
application/json
curl -X GET "https://example.com/oauth/authorize?response_type=code&client_id=string&redirect_uri=http%3A%2F%2Fexample.com&code_challenge=string&code_challenge_method=S256""string"{
"error": "string",
"error_description": "string"
}{
"type": "string",
"title": "string",
"detail": "string",
"trace_id": "string",
"metadata": {}
}Auth Provider Logout POST
Performs a HTTP logout by clearing the session cookie and redirecting to to the requested path at the frontend's `WEB_ADDRESS`. Typically this may be a secondary logout route on the frontend implementation that can handle any frontend-specific logout tasks. This is necessary in cases where the frontend is running on a different origin to the API service such as api.site.com vs site.com because Clear-Site-Data and other headers are same-origin compliant and won't work cross-origin.
O Auth Authorise Consent GET
Read a pending OAuth authorisation code request for a signed-in user before they approve or deny consent. This is a Storyden frontend/API integration endpoint, not an OAuth protocol endpoint. It returns the client, redirect URI, requested scopes, and currently grantable scopes so a caller can render a consent screen or, for headless integrations, decide programmatically. Accepts either a browser session or a personal access key.