App ID oauth-flows

Introduction With IBM Cloud® App ID, you can secure resources and add authentication, even when you don't have a lot of security experience. By requiring users to sign in to your app, you can store user data such as preferences or information from their public social profiles that you can use to customize each experience of your app. Most major frameworks are supported because App ID is based on OIDC. For help getting started in specific languages, see the tutorials for Pythonhttps://github.com/mnsn/appid-python-flask-example, Node.jshttps://www.ibm.com/cloud/blog/securing-angularnode-js-applications-using-app-id, and Gohttps://www.ibm.com/cloud/blog/creating-go-applications-with-app-id. Endpoint URLs App ID supports region-specific endpoint URLs that you can use to interact with the service over public service endpointshttps://cloud.ibm.com/docs/appid?topic=appid-regions-endpoints. To make requests to the Authorization API, you supply the endpoint URL that corresponds with the location where your App ID service instance resides. Endpoint URLs by location - Dallas: https://us-south.appid.cloud.ibm.com - Frankfurt: https://eu-de.appid.cloud.ibm.com - London: https://eu-gb.appid.cloud.ibm.com - Osaka: https://jp-osa.appid.cloud.ibm.com - Sao Paulo: https://br-sao.appid.cloud.ibm.com - Sydney: https://au-syd.appid.cloud.ibm.com - Tokyo: https://jp-tok.appid.cloud.ibm.com - Toronto: https://ca-tor.appid.cloud.ibm.com - Washington: https://us-east.appid.cloud.ibm.com Base URL https://{region}.appid.cloud.ibm.com Authentication You might use one of two authentication methods when you interact with this API. If one of the following options is not used, the API is unprotected and does not require authorization. For more information and help obtaining your credentials and an access token, see obtaining tokenshttps://cloud.ibm.com/docs/appid?topic=appid-obtain-tokens. Basic authentication A client ID and secret can be found in the Service Credentials or Applications tab of the App ID dashboard. Example: Authorization basic base64{client ID}:{secret} App ID access token When users or backend services interact with your app, they might need to be authorized to perform specific actions. App ID verifies that the entity that makes the request is authorized and returns access an access token to your app. Auditing You can monitor API activity within your account by using the IBM Cloud Activity Tracker service. Whenever an API method is called, an event is generated that you can then track and audit from within Activity Tracker. The specific event type is listed for each individual method. For more information about how to track App ID activity, see Auditing events for App IDhttps://cloud.ibm.com/docs/appid?topic=appid-at-events. Error handling The App ID APIs use standard HTTP status codeshttps://cloud.ibm.com/docs/api-handbook?topic=api-handbook-status-codes to indicate whether a method completed successfully. HTTP response codes in the 2xx range indicate success. A response in the 4xx range is some sort of failure, and a response in the 5xx range usually indicates an internal system error.

MethodPathSummary
OPTIONS/oauth/v4/{tenantId}/userinfoUser Info Preflight
POST/oauth/v4/{tenantId}/userinfoRetrieve user information
GET/oauth/v4/{tenantId}/userinfoRetrieve user information
POST/oauth/v4/{tenantId}/activity_loggingLog user activity
POST/oauth/v4/{tenantId}/clientsRegister client
GET/oauth/v4/{tenantId}/authorizationAuthorization
OPTIONS/oauth/v4/{tenantId}/tokenToken preflight
POST/oauth/v4/{tenantId}/tokenToken
POST/oauth/v4/{tenantId}/revokeRevoke refresh token
POST/oauth/v4/{tenantId}/introspectIntrospect tokens
GET/oauth/v4/{tenantId}/publickeysPublic keys retrival
OPTIONS/oauth/v4/{tenantId}/publickeysPublic keys preflight
GET/oauth/v4/{tenantId}/cloud_directory/generate_codeGenerate temporary code
GET/oauth/v4/{tenantId}/.well-known/openid-configurationDiscovery
GET/oauth/v4/{tenantId}/cloud_directory/sso/logoutLogout a current SSO session
OPTIONS/oauth/v4/{tenantId}/introspectIntrospect tokens preflight