API & OAuth 2.1
For third-party integrations: OAuth discovery, authorization code + PKCE flow, and short-lived tokens.
Beyond personal access tokens, the server implements OAuth 2.1 for multi-user integrations: PKCE is mandatory, alongside rotating refresh tokens.
Discovery
RFC 8414-compatible clients automatically discover the authorization server configuration:
curl https://weflow-backend-v1-production.up.railway.app/.well-known/oauth-authorization-server
4-step flow
- 1
Generate PKCE challenge
code_challenge = BASE64URL(SHA256(code_verifier)). Plain challenge method is rejected.
- 2
Redirect to /authorize
The user reviews requested scopes on the consent screen and approves or declines.
- 3
Receive authorization code
Browser redirects back to your redirect_uri with ?code=…&state=…. Single-use with 5-minute TTL.
- 4
Exchange code for tokens
POST /api/mcp/oauth/token with grant_type=authorization_code, code_verifier, and client_id.