Skip to content

OAuth

client.oauth: /oauth/authorize and /api/v1/oauth/...

Bases: Resource

OAuth2 and OpenID Connect: build sign-in links, exchange codes, read the user's claims.

Most apps use sweatstack.fastapi or sweatstack.streamlit, which do this for you.

authorization_url(*, client_id, redirect_uri, code_challenge=None, scope='data:read data:write profile', prompt='none', state=None)

Builds the URL to send a user to for signing in with SweatStack.

Endpoint: GET /oauth/authorize

Parameters:

  • client_id (str) –

    Your app's client ID.

  • redirect_uri (str) –

    Where SweatStack sends the user back to; must be registered.

  • code_challenge (str | None, default: None ) –

    A PKCE challenge from :meth:generate_pkce_params.

  • scope (str, default: 'data:read data:write profile' ) –

    Space-separated scopes.

  • prompt (str | None, default: 'none' ) –

    The OAuth prompt; None to omit it.

  • state (str | None, default: None ) –

    An opaque value to check on the way back, against CSRF.

Returns:

  • str ( str ) –

    The authorization URL.

Examples:

from sweatstack import Client

client = Client()
verifier, challenge = client.oauth.generate_pkce_params()
url = client.oauth.authorization_url(
    client_id="YOUR_CLIENT_ID",
    redirect_uri="http://localhost:8000/callback",
    code_challenge=challenge,
)

exchange_code(code, *, client_id, code_verifier=None, client_secret=None, persist=True)

Exchanges an authorization code for tokens, and signs this client in with them.

Endpoint: POST /api/v1/oauth/token

Parameters:

  • code (str) –

    The code from the redirect back to your app.

  • client_id (str) –

    Your app's client ID.

  • code_verifier (str | None, default: None ) –

    The PKCE verifier, if you sent a challenge.

  • client_secret (str | None, default: None ) –

    Your app's secret, for confidential clients.

  • persist (bool, default: True ) –

    Also save the tokens to this machine's token storage.

Returns:

  • TokenResponse ( TokenResponse ) –

    access_token, refresh_token and their metadata.

Raises:

Examples:

from sweatstack import Client

client = Client()
tokens = client.oauth.exchange_code(
    "code-from-redirect", client_id="YOUR_CLIENT_ID", code_verifier="verifier"
)

generate_pkce_params()

Generates a PKCE code verifier and its S256 code challenge.

Returns:

  • str –

    tuple[str, str]: (code_verifier, code_challenge). Send the challenge with

  • str –

    meth:authorization_url; keep the verifier for :meth:exchange_code.

Examples:

from sweatstack import Client

client = Client()
verifier, challenge = client.oauth.generate_pkce_params()

userinfo()

Retrieves the OpenID Connect claims of the user, and why they may have no data.

Endpoint: GET /api/v1/oauth/userinfo

Requires the profile scope. Besides sub, name, given_name, family_name, email and registered_at, the response has issue (beta): None when there is nothing to say, otherwise the one thing to tell the user now. issue.destination says the user can fix it in the Portal: pass it to client.portal.sessions.create() when they click. It is None on delegated tokens and on syncing or unavailable issues, so show a button only when it is set. Without the profile scope, client.profile.status() gives the same issue.

Returns:

Raises:

Examples:

from sweatstack import Client

client = Client()
user = client.oauth.userinfo()
if user.issue:
    print(user.issue.message)