OAuth 2.1 authorization endpoint

Authorization Code + PKCE entry point. Unauthenticated browsers are redirected to /api/oauth/login → /api/oauth/consent → back here on accept. Returns 302 to the client redirect_uri with code + state.

GET/api/auth/oauth2/authorize

Query Parameters

client_id*string
redirect_uri*string
Formaturi
response_type*string
Value in"code"
scope*string
state?string
code_challenge*string
code_challenge_method*string
Value in"S256"
resource?string

RFC 8707 resource indicator.

Formaturi
curl -X GET "https://your-instance/api/auth/oauth2/authorize?client_id=string&redirect_uri=http%3A%2F%2Fexample.com&response_type=code&scope=string&code_challenge=string&code_challenge_method=S256"
Empty
Empty
{
  "error": "string",
  "error_description": "string"
}
{
  "error": "temporarily_unavailable",
  "error_description": "string"
}