Light Authorization API

The Authorization API from Light — 2 operation(s) for authorization.

OpenAPI Specification

light-authorization-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Light Authorization API
  version: 1.0.0
security:
- apiKeyAuth: []
- bearerAuth: []
tags:
- name: Authorization
paths:
  /oauth/token:
    post:
      tags:
      - Authorization
      summary: Create access token
      description: Exchanges an authorization code or refresh token for an access token
      operationId: getOAuthToken
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                client_id:
                  type: string
                client_secret:
                  type: string
                grant_type:
                  type: string
                code:
                  type: string
                redirect_uri:
                  type: string
                refresh_token:
                  type: string
      responses:
        default:
          description: default response
          content:
            application/json;charset=UTF-8:
              schema:
                $ref: '#/components/schemas/ExternalOauthToken'
  /oauth/authorize:
    get:
      tags:
      - Authorization
      summary: Start authorization flow
      description: Redirects the user to the authorization page to start the OAuth V2 authorization flow
      operationId: startOAuthAuthorizationFlow
      parameters:
      - name: redirect_uri
        in: query
        schema:
          type: string
      - name: state
        in: query
        schema:
          type: string
      - name: client_id
        in: query
        schema:
          type: string
      responses:
        default:
          description: default response
          content:
            application/json;charset=UTF-8: {}
components:
  schemas:
    ExternalOauthToken:
      type: object
      properties:
        access_token:
          type: string
        expires_in:
          type: integer
          format: int64
        token_type:
          type: string
        refresh_token:
          type: string
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      description: Basic authentication header of the form **Basic** **<api_key>**, where **<api_key>** is your api key.
      name: Authorization
      in: header
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT