API & OAuth 2.1

For third-party integrations: OAuth discovery, authorization code + PKCE flow, and short-lived tokens.

Beyond personal access tokens, the server implements OAuth 2.1 for multi-user integrations: PKCE is mandatory, alongside rotating refresh tokens.

OAuth 2.1 flow diagram
Authorization code + PKCE flow, from initial redirection to token exchange.

Discovery

RFC 8414-compatible clients automatically discover the authorization server configuration:

code
curl https://weflow-backend-v1-production.up.railway.app/.well-known/oauth-authorization-server

4-step flow

  1. 1

    Generate PKCE challenge

    code_challenge = BASE64URL(SHA256(code_verifier)). Plain challenge method is rejected.

  2. 2

    Redirect to /authorize

    The user reviews requested scopes on the consent screen and approves or declines.

  3. 3

    Receive authorization code

    Browser redirects back to your redirect_uri with ?code=…&state=…. Single-use with 5-minute TTL.

  4. 4

    Exchange code for tokens

    POST /api/mcp/oauth/token with grant_type=authorization_code, code_verifier, and client_id.