AApt Commerce
Sign inGet started
Show for
Planned surfacePR-CDocs · Learn

OAuth 2.0 for partners

Developer guide covering the Authorization Code + PKCE flow, consent screen, token refresh, scope model, and revocation.

This page is a stub

The route exists so navigation is complete and links don't 404, but the interactive surface has not shipped yet. The list below is the intended scope. Nothing here is wired to real data.

Will include

  • End-to-end flow diagram (client → authorize → consent → callback → token)
  • PKCE requirement + example code_verifier / code_challenge
  • Scope model tied to IntentPicker capabilities
  • Consent screen contract for merchants
  • Token refresh + rotation
  • Revocation + client secret rotation
  • Client Credentials flow (server-to-server) — when to use

Depends on

  • · PR-C · OAuth client registration UI ships first

Related surfaces that exist today