> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sharedgraph.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Provider public-client

> Provider browser-flow helper requiring an authenticated maintained account cookie. This is not social bearer authority. POST requires exact network Origin; clients normally reach it through the first-party consent UI.



## OpenAPI

````yaml /openapi.json get /api/auth/oauth2/public-client
openapi: 3.1.0
info:
  title: SharedGraph public application API
  version: pilot
  description: >-
    Pilot: breaking changes are possible and announced in the changelog.
    SharedGraph is a common social network used through independently operated
    applications. Supported integration: server-backed confidential OAuth client
    using authorization code with S256 PKCE. Anonymous public reads are a pilot
    convenience: 120 requests/minute per connecting address, with a tighter
    shared 30/minute events+reconcile budget. Signed-in views must preserve
    bearer safety rules and never fall back to anonymous after a refusal. No
    account-management, moderator, operator, registration or debug API is part
    of this reference. Provider browser helpers use account cookies; token
    endpoints use Basic; social private reads and mutations use bearer.
    x-app-generation is an application BFF session signal, not a core response
    header. Error catalog below records the pilot domain and OAuth protocol
    refusals; provider error descriptions are diagnostic text, not a stable
    machine identifier.
servers:
  - url: https://api.sharedgraph.com
    description: Hosted pilot network
security:
  - BearerAuth: []
tags:
  - name: Social
  - name: OAuth
  - name: Discovery
paths:
  /api/auth/oauth2/public-client:
    get:
      tags:
        - OAuth
      summary: Provider public-client
      description: >-
        Provider browser-flow helper requiring an authenticated maintained
        account cookie. This is not social bearer authority. POST requires exact
        network Origin; clients normally reach it through the first-party
        consent UI.
      operationId: get_api_auth_oauth2_public_client
      parameters:
        - name: client_id
          in: query
          required: true
          schema:
            type: string
            minLength: 1
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicClient'
        '400':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '401':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '403':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '404':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '405':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '409':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '413':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '415':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '429':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '500':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '503':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
      security:
        - ProviderAccountSession: []
components:
  schemas:
    PublicClient:
      type: object
      properties:
        client_id:
          type: string
        client_name:
          anyOf:
            - type: string
            - type: 'null'
        client_uri:
          anyOf:
            - type: string
              format: uri
            - type: 'null'
        contacts:
          anyOf:
            - type: array
              items:
                type: string
            - type: 'null'
        logo_uri:
          anyOf:
            - type: string
              format: uri
            - type: 'null'
        tos_uri:
          anyOf:
            - type: string
              format: uri
            - type: 'null'
        policy_uri:
          anyOf:
            - type: string
              format: uri
            - type: 'null'
        redirect_uris:
          type: array
          items:
            type: string
            format: uri
        post_logout_redirect_uris:
          type: array
          items:
            type: string
            format: uri
      required:
        - client_id
        - redirect_uris
      additionalProperties: false
    OAuthError:
      oneOf:
        - $ref: '#/components/schemas/Error'
        - $ref: '#/components/schemas/ProviderError'
    Error:
      type: object
      properties:
        error:
          type: string
          minLength: 1
          enum:
            - unknown_or_immutable_field
            - invalid_text
            - invalid_json
            - intent_required
            - unsupported_audience
            - invalid_parent
            - revision_required
            - self_relation
            - self_block
            - invalid_report
            - invalid_cursor
            - authentication_required
            - auth_unavailable
            - authority_unavailable
            - capability_required
            - not_owner
            - interaction_unavailable
            - social_authority_required
            - not_found
            - intent_conflict
            - revision_conflict
            - post_deleted
            - post_unavailable
            - parent_unavailable
            - effect_mismatch
            - domain_plan_too_large
            - publishing_paused
            - pilot_rate_limited
            - protected_read_unavailable
            - protected_read_storage_unavailable
            - recovery_unavailable
            - domain_storage_unavailable
            - pilot_storage_unavailable
            - pilot_limits_unavailable
            - trusted_address_unavailable
            - origin_required
            - origin_mismatch
            - restriction_witness_required
            - restriction_witness_unavailable_or_incomplete
            - recovery_state_missing
            - recovery_publication_changed
            - recovery_quarantined
            - lifecycle_revision_conflict
            - witness_prepare_mismatch
            - ambiguous_acceptance_requires_independent_proof
            - witness_acceptance_mismatch
            - witness_finalize_unconfirmed
            - invalid_request
            - invalid_client
            - invalid_grant
            - invalid_scope
            - unsupported_grant_type
            - unsupported_response_type
            - access_denied
            - temporarily_unavailable
            - server_error
            - invalid_token
            - unsupported_token_type
            - invalid_target
            - invalid_signature
            - invalid_redirect_uri
            - invalid_request_uri
            - request_not_supported
            - request_uri_not_supported
            - login_required
            - interaction_required
            - account_selection_required
            - consent_required
        message:
          type: string
        error_description:
          type: string
        error_uri:
          type: string
          format: uri
      required:
        - error
      additionalProperties: false
    ProviderError:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          enum:
            - UNAUTHORIZED
            - VALIDATION_ERROR
            - TOO_MANY_REQUESTS
            - FORBIDDEN
            - BAD_REQUEST
            - INTERNAL_SERVER_ERROR
            - NOT_FOUND
            - METHOD_NOT_ALLOWED
            - UNSUPPORTED_MEDIA_TYPE
        message:
          type: string
      additionalProperties: false
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Audited access token bound to the current application, actor and
        immutable grant.
    ProviderAccountSession:
      type: apiKey
      in: cookie
      name: better-auth.session_token
      description: >-
        Maintained provider account session; use the first-party login and
        consent UI. HTTPS deployments use the provider secure cookie prefix;
        this is a browser UI detail, not an application credential.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.