> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sharedgraph.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Start authorization code with PKCE

> Browser navigation to the provider. An account login and deliberate consent are required before a code is issued. The account cookie is provider UI authority, never social API authority. Use a confidential server-backed client, exact registered redirect URI, S256 PKCE, state and nonce. Resources are unsupported.



## OpenAPI

````yaml /openapi.json post /api/auth/oauth2/authorize
openapi: 3.1.0
info:
  title: SharedGraph public application API
  version: pilot
  description: >-
    Pilot: breaking changes are possible and announced in the changelog.
    SharedGraph is a common social network used through independently operated
    applications. Supported integration: server-backed confidential OAuth client
    using authorization code with S256 PKCE. Anonymous public reads are a pilot
    convenience: 120 requests/minute per connecting address, with a tighter
    shared 30/minute events+reconcile budget. Signed-in views must preserve
    bearer safety rules and never fall back to anonymous after a refusal. No
    account-management, moderator, operator, registration or debug API is part
    of this reference. Provider browser helpers use account cookies; token
    endpoints use Basic; social private reads and mutations use bearer.
    x-app-generation is an application BFF session signal, not a core response
    header. Error catalog below records the pilot domain and OAuth protocol
    refusals; provider error descriptions are diagnostic text, not a stable
    machine identifier.
servers:
  - url: https://api.sharedgraph.com
    description: Hosted pilot network
security:
  - BearerAuth: []
tags:
  - name: Social
  - name: OAuth
  - name: Discovery
paths:
  /api/auth/oauth2/authorize:
    post:
      tags:
        - OAuth
      summary: Start authorization code with PKCE
      description: >-
        Browser navigation to the provider. An account login and deliberate
        consent are required before a code is issued. The account cookie is
        provider UI authority, never social API authority. Use a confidential
        server-backed client, exact registered redirect URI, S256 PKCE, state
        and nonce. Resources are unsupported.
      operationId: post_api_auth_oauth2_authorize
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                response_type:
                  type: string
                  enum:
                    - code
                client_id:
                  type: string
                  minLength: 1
                redirect_uri:
                  type: string
                  format: uri
                scope:
                  type: string
                state:
                  type: string
                  minLength: 1
                nonce:
                  type: string
                  minLength: 1
                code_challenge:
                  type: string
                  minLength: 1
                code_challenge_method:
                  type: string
                  enum:
                    - S256
                prompt:
                  type: string
                  enum:
                    - consent
              required:
                - response_type
                - client_id
                - redirect_uri
                - scope
                - state
                - nonce
                - code_challenge
                - code_challenge_method
              additionalProperties: false
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RedirectURL'
        '302':
          description: >-
            Navigate to account login, consent or the registered callback; never
            log Location.
          headers:
            Location:
              required: true
              schema:
                type: string
                format: uri-reference
        '400':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '401':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '403':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '404':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '405':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '409':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '413':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '415':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '429':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
          headers:
            Retry-After:
              description: Positive integer seconds until the anonymous window resets.
              required: true
              schema:
                type: string
                pattern: ^[1-9][0-9]*$
        '500':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
        '503':
          description: Refusal; see the error catalog.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuthError'
      security: []
components:
  schemas:
    RedirectURL:
      type: object
      properties:
        url:
          type: string
          format: uri-reference
          description: >-
            Provider navigation target. Consent callbacks are absolute;
            continuation can return a relative consent URL. Resolve against the
            issuer origin and never log the query.
        redirect:
          const: true
          type: boolean
      required:
        - url
        - redirect
      additionalProperties: false
    OAuthError:
      oneOf:
        - $ref: '#/components/schemas/Error'
        - $ref: '#/components/schemas/ProviderError'
    Error:
      type: object
      properties:
        error:
          type: string
          minLength: 1
          enum:
            - unknown_or_immutable_field
            - invalid_text
            - invalid_json
            - intent_required
            - unsupported_audience
            - invalid_parent
            - revision_required
            - self_relation
            - self_block
            - invalid_report
            - invalid_cursor
            - authentication_required
            - auth_unavailable
            - authority_unavailable
            - capability_required
            - not_owner
            - interaction_unavailable
            - social_authority_required
            - not_found
            - intent_conflict
            - revision_conflict
            - post_deleted
            - post_unavailable
            - parent_unavailable
            - effect_mismatch
            - domain_plan_too_large
            - publishing_paused
            - pilot_rate_limited
            - protected_read_unavailable
            - protected_read_storage_unavailable
            - recovery_unavailable
            - domain_storage_unavailable
            - pilot_storage_unavailable
            - pilot_limits_unavailable
            - trusted_address_unavailable
            - origin_required
            - origin_mismatch
            - restriction_witness_required
            - restriction_witness_unavailable_or_incomplete
            - recovery_state_missing
            - recovery_publication_changed
            - recovery_quarantined
            - lifecycle_revision_conflict
            - witness_prepare_mismatch
            - ambiguous_acceptance_requires_independent_proof
            - witness_acceptance_mismatch
            - witness_finalize_unconfirmed
            - invalid_request
            - invalid_client
            - invalid_grant
            - invalid_scope
            - unsupported_grant_type
            - unsupported_response_type
            - access_denied
            - temporarily_unavailable
            - server_error
            - invalid_token
            - unsupported_token_type
            - invalid_target
            - invalid_signature
            - invalid_redirect_uri
            - invalid_request_uri
            - request_not_supported
            - request_uri_not_supported
            - login_required
            - interaction_required
            - account_selection_required
            - consent_required
        message:
          type: string
        error_description:
          type: string
        error_uri:
          type: string
          format: uri
      required:
        - error
      additionalProperties: false
    ProviderError:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: string
          enum:
            - UNAUTHORIZED
            - VALIDATION_ERROR
            - TOO_MANY_REQUESTS
            - FORBIDDEN
            - BAD_REQUEST
            - INTERNAL_SERVER_ERROR
            - NOT_FOUND
            - METHOD_NOT_ALLOWED
            - UNSUPPORTED_MEDIA_TYPE
        message:
          type: string
      additionalProperties: false
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Audited access token bound to the current application, actor and
        immutable grant.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.