تخطَّ إلى المحتوى

@dukkan.one/app-sdk/oauth

PKCE, the consent URL, the code exchange and the refresh grant, exactly as the platform's token endpoint expects them.

الحزمة
@dukkan.one/app-sdk@0.3.0
مراجعة الواجهة
2026-09-10
الاستيراد
import { … } from "@dukkan.one/app-sdk/oauth"
في هذه الصفحة

الدوال

buildAuthorizeUrl#

function buildAuthorizeUrl(input: AuthorizeUrlInput): string

The consent URL a merchant is sent to (docs/apps/authorization#authorize).

exchangeCode#

function exchangeCode(input: ExchangeCodeInput): Promise<TokenResponse>

Redeems the authorization code from the callback for the first token pair. The response carries install_id, store_id and store_slug; key your storage on the ids.

generatePkce#

function generatePkce(): Promise<PkcePair>

PKCE S256 (RFC 7636); pinned by packages/contracts/vectors/pkce.json.

generateState#

function generateState(): string

A random state value (16 bytes, base64url) to bind the callback to the request that started it.

parseCallbackQuery#

function parseCallbackQuery(query: URLSearchParams | Record<string, string | undefined>): { ok: true; code: string; state: string; } | { ok: false; error: string; state: string; }

Parses the query the platform appends to redirect_uri. A consent denial or a platform-side refusal arrives as error (with state echoed).

pkceChallenge#

function pkceChallenge(verifier: string): Promise<string>

The S256 challenge for a verifier: base64url(sha256(verifier)).

refreshTokens#

function refreshTokens(input: RefreshInput): Promise<TokenResponse>

Presents a refresh token for a new pair. Rotation is single-use: presenting the same token twice revokes the install (a 30 second leeway covers a race between two instances). Prefer TokenManager, which serialises refreshes through your store's lock.

الواجهات

AuthorizeUrlInput#

interface AuthorizeUrlInput

Everything the consent URL needs; installToken carries a private or development distribution token.

الأعضاء
الاسمالنوعالوصف
apiUrlstring | undefined
clientIdمطلوبstring
redirectUriمطلوبstring
scopesمطلوبReadonlyArray<string>
stateمطلوبstring
codeChallengeمطلوبstring
installTokenstring | null | undefined

Private or development distribution token from the marketplace listing or dukkan app dev.

ExchangeCodeInput#

interface ExchangeCodeInput

Input of exchangeCode: the platform origin, your client credentials, the code, the exact redirect URI and the PKCE verifier from the first hop.

الأعضاء
الاسمالنوعالوصف
apiUrlstring | undefined
credentialsمطلوبOAuthClientCredentials
codeمطلوبstring
redirectUriمطلوبstring
codeVerifierمطلوبstring
fetch((input: RequestInfo | URL, init?: RequestInit) => Promise<Response>) | undefined
timeoutMsnumber | undefined

OAuthClientCredentials#

interface OAuthClientCredentials

Your app's client id and secret. The secret may be a function so a rotated value is read at call time.

الأعضاء
الاسمالنوعالوصف
clientIdمطلوبstring
clientSecretمطلوبstring | (() => string)

The secret, or a function returning it (read at call time so rotation needs no restart).

PkcePair#

interface PkcePair

A PKCE verifier and its S256 challenge.

الأعضاء
الاسمالنوعالوصف
verifierمطلوبstring

43 base64url characters; keep it server-side until the callback.

challengeمطلوبstring

S256 challenge to send on the authorize URL.

RefreshInput#

interface RefreshInput

Input of refreshTokens: the platform origin, your client credentials and the current refresh token.

الأعضاء
الاسمالنوعالوصف
apiUrlstring | undefined
credentialsمطلوبOAuthClientCredentials
refreshTokenمطلوبstring
fetch((input: RequestInfo | URL, init?: RequestInit) => Promise<Response>) | undefined
timeoutMsnumber | undefined

TokenResponse#

interface TokenResponse

What /apps/oauth/token returns on both grants (identity fields since 2026-09-09).

الأعضاء
الاسمالنوعالوصف
access_tokenمطلوبstring
token_typeمطلوب"Bearer"
expires_inمطلوبnumber
refresh_tokenمطلوبstring
scopestring | undefined
install_idstring | undefined
store_idstring | undefined
store_slugstring | undefined

الثوابت

DEFAULT_API_URL#

const DEFAULT_API_URL: "https://dukkan.one"

Where the merchant platform lives; every OAuth and API path hangs off it.

OAUTH_AUTHORIZE_PATH#

const OAUTH_AUTHORIZE_PATH: "/apps/oauth/authorize"

Path of the consent screen on the platform origin.

OAUTH_TOKEN_PATH#

const OAUTH_TOKEN_PATH: "/apps/oauth/token"

Path of the token endpoint on the platform origin.