Introduction With IBM Cloud® App ID, you can secure resources and add authentication, even when you don't have a lot of security experience. By requiring users to sign in to your app, you can store user data such as preferences or information from their public social profiles that you can use to customize each experience of your app. Most major frameworks are supported because App ID is based on OIDC. For help getting started in specific languages, see the tutorials for Pythonhttps://github.com/mnsn/appid-python-flask-example, Node.jshttps://www.ibm.com/cloud/blog/securing-angularnode-js-applications-using-app-id, and Gohttps://www.ibm.com/cloud/blog/creating-go-applications-with-app-id. Endpoint URLs App ID supports region-specific endpoint URLs that you can use to interact with the service over public service endpointshttps://cloud.ibm.com/docs/appid?topic=appid-regions-endpoints. To make requests to the Authorization API, you supply the endpoint URL that corresponds with the location where your App ID service instance resides. Endpoint URLs by location - Dallas: https://us-south.appid.cloud.ibm.com - Frankfurt: https://eu-de.appid.cloud.ibm.com - London: https://eu-gb.appid.cloud.ibm.com - Osaka: https://jp-osa.appid.cloud.ibm.com - Sao Paulo: https://br-sao.appid.cloud.ibm.com - Sydney: https://au-syd.appid.cloud.ibm.com - Tokyo: https://jp-tok.appid.cloud.ibm.com - Toronto: https://ca-tor.appid.cloud.ibm.com - Washington: https://us-east.appid.cloud.ibm.com Base URL https://{region}.appid.cloud.ibm.com Authentication You might use one of two authentication methods when you interact with this API. If one of the following options is not used, the API is unprotected and does not require authorization. For more information and help obtaining your credentials and an access token, see obtaining tokenshttps://cloud.ibm.com/docs/appid?topic=appid-obtain-tokens. Basic authentication A client ID and secret can be found in the Service Credentials or Applications tab of the App ID dashboard. Example: Authorization basic base64{client ID}:{secret} App ID access token When users or backend services interact with your app, they might need to be authorized to perform specific actions. App ID verifies that the entity that makes the request is authorized and returns access an access token to your app. Auditing You can monitor API activity within your account by using the IBM Cloud Activity Tracker service. Whenever an API method is called, an event is generated that you can then track and audit from within Activity Tracker. The specific event type is listed for each individual method. For more information about how to track App ID activity, see Auditing events for App IDhttps://cloud.ibm.com/docs/appid?topic=appid-at-events. Error handling The App ID APIs use standard HTTP status codeshttps://cloud.ibm.com/docs/api-handbook?topic=api-handbook-status-codes to indicate whether a method completed successfully. HTTP response codes in the 2xx range indicate success. A response in the 4xx range is some sort of failure, and a response in the 5xx range usually indicates an internal system error.
| Method | Path | Summary |
|---|---|---|
| OPTIONS | /oauth/v4/{tenantId}/userinfo | User Info Preflight |
| POST | /oauth/v4/{tenantId}/userinfo | Retrieve user information |
| GET | /oauth/v4/{tenantId}/userinfo | Retrieve user information |
| POST | /oauth/v4/{tenantId}/activity_logging | Log user activity |
| POST | /oauth/v4/{tenantId}/clients | Register client |
| GET | /oauth/v4/{tenantId}/authorization | Authorization |
| OPTIONS | /oauth/v4/{tenantId}/token | Token preflight |
| POST | /oauth/v4/{tenantId}/token | Token |
| POST | /oauth/v4/{tenantId}/revoke | Revoke refresh token |
| POST | /oauth/v4/{tenantId}/introspect | Introspect tokens |
| GET | /oauth/v4/{tenantId}/publickeys | Public keys retrival |
| OPTIONS | /oauth/v4/{tenantId}/publickeys | Public keys preflight |
| GET | /oauth/v4/{tenantId}/cloud_directory/generate_code | Generate temporary code |
| GET | /oauth/v4/{tenantId}/.well-known/openid-configuration | Discovery |
| GET | /oauth/v4/{tenantId}/cloud_directory/sso/logout | Logout a current SSO session |
| OPTIONS | /oauth/v4/{tenantId}/introspect | Introspect tokens preflight |