Request Authorization (OAuth app PKCE)

Start the PKCE authorization-code flow for an OAuth app.

Use this endpoint only for OAuth app credentials that require a Spendesk user to authorize access. Do not use it with Public API credentials; server-to-server Public API credentials should request a bearer token from Create Access Token.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Query Params
string
enum
required

Always code.

Allowed:
uuid
required
length ≥ 1

OAuth app client_id provided by Spendesk.

uri
required
length ≥ 1

URI to redirect the user after connection is authorized. If successful, the redirect URL will look like: {redirect_uri}?code={auth_code}&state={state}, where code is the authorization code to be used in the Request Access Token endpoint, and state allows you to verify the integrity of the connection.

string
required

Optional field to restrict the scope of the token. The default scope will match the scope defined in the front end when generating your API client id and secret.

See available scopes for more information.

string

This string will be sent back at the end of the OAuth2 flow, so that whoever starts the flow can double-check that the same variable is being returned (and there has been no tampering).

string
required
length ≥ 1

The client should locally generate a secret (AKA code_verifier), that at this initial stage of the OAuth2 flow should be passed as a code_challenge in the format of base64url(sha256(secret)). You can find an example about that here.

string
enum
Defaults to S256

Always S256.

Allowed:
string

Optional RFC 8707 resource indicator. Ignored for standard OAuth clients — any value (including an empty string) is accepted and never read. For public MCP dynamic client registration clients it is required and must match the MCP resource URL; that check is enforced in business logic once the client is resolved.

Responses

Language
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json