@dukkan.one/app-sdk/oauth
PKCE, the consent URL, the code exchange and the refresh grant, exactly as the platform's token endpoint expects them.
- الحزمة
@dukkan.one/app-sdk@0.3.0- مراجعة الواجهة
2026-09-10- الاستيراد
import { … } from "@dukkan.one/app-sdk/oauth"
في هذه الصفحة
الدوال
buildAuthorizeUrl#
The consent URL a merchant is sent to (docs/apps/authorization#authorize).
exchangeCode#
Redeems the authorization code from the callback for the first token pair. The response carries install_id, store_id and store_slug; key your storage on the ids.
generatePkce#
PKCE S256 (RFC 7636); pinned by packages/contracts/vectors/pkce.json.
generateState#
A random state value (16 bytes, base64url) to bind the callback to the request that started it.
parseCallbackQuery#
Parses the query the platform appends to redirect_uri. A consent denial
or a platform-side refusal arrives as error (with state echoed).
pkceChallenge#
The S256 challenge for a verifier: base64url(sha256(verifier)).
refreshTokens#
Presents a refresh token for a new pair. Rotation is single-use: presenting the same token twice revokes the install (a 30 second leeway covers a race between two instances). Prefer TokenManager, which serialises refreshes through your store's lock.
الواجهات
AuthorizeUrlInput#
Everything the consent URL needs; installToken carries a private or development distribution token.
| الاسم | النوع | الوصف |
|---|---|---|
apiUrl | string | undefined | |
clientIdمطلوب | string | |
redirectUriمطلوب | string | |
scopesمطلوب | ReadonlyArray<string> | |
stateمطلوب | string | |
codeChallengeمطلوب | string | |
installToken | string | null | undefined | Private or development distribution token from the marketplace listing or |
ExchangeCodeInput#
Input of exchangeCode: the platform origin, your client credentials, the code, the exact redirect URI and the PKCE verifier from the first hop.
| الاسم | النوع | الوصف |
|---|---|---|
apiUrl | string | undefined | |
credentialsمطلوب | OAuthClientCredentials | |
codeمطلوب | string | |
redirectUriمطلوب | string | |
codeVerifierمطلوب | string | |
fetch | ((input: RequestInfo | URL, init?: RequestInit) => Promise<Response>) | undefined | |
timeoutMs | number | undefined |
OAuthClientCredentials#
Your app's client id and secret. The secret may be a function so a rotated value is read at call time.
| الاسم | النوع | الوصف |
|---|---|---|
clientIdمطلوب | string | |
clientSecretمطلوب | string | (() => string) | The secret, or a function returning it (read at call time so rotation needs no restart). |
PkcePair#
A PKCE verifier and its S256 challenge.
| الاسم | النوع | الوصف |
|---|---|---|
verifierمطلوب | string | 43 base64url characters; keep it server-side until the callback. |
challengeمطلوب | string | S256 challenge to send on the authorize URL. |
RefreshInput#
Input of refreshTokens: the platform origin, your client credentials and the current refresh token.
| الاسم | النوع | الوصف |
|---|---|---|
apiUrl | string | undefined | |
credentialsمطلوب | OAuthClientCredentials | |
refreshTokenمطلوب | string | |
fetch | ((input: RequestInfo | URL, init?: RequestInit) => Promise<Response>) | undefined | |
timeoutMs | number | undefined |
TokenResponse#
What /apps/oauth/token returns on both grants (identity fields since 2026-09-09).
| الاسم | النوع | الوصف |
|---|---|---|
access_tokenمطلوب | string | |
token_typeمطلوب | "Bearer" | |
expires_inمطلوب | number | |
refresh_tokenمطلوب | string | |
scope | string | undefined | |
install_id | string | undefined | |
store_id | string | undefined | |
store_slug | string | undefined |
الثوابت
DEFAULT_API_URL#
Where the merchant platform lives; every OAuth and API path hangs off it.
OAUTH_AUTHORIZE_PATH#
Path of the consent screen on the platform origin.
OAUTH_TOKEN_PATH#
Path of the token endpoint on the platform origin.