Documentation

Quickstart

Register an app, sign in a Davi user, and make your first API call.

In this tutorial you register a server-side app, sign in a Davi user with it, and use their token to fetch their account from the API. The API is served under https://api.davi.social/api/v1 and every request carries an OAuth 2.0 bearer token.

You need a Davi account that owns or manages an organization, because apps are registered per organization, and access to the Davi dashboard.

1. Register an app

In the dashboard, open your organization and go to Developer → Apps → Create app. Choose Server-side application. This is a confidential client: it receives a client_secret.

Add the redirect URI https://yourapp.com/callback, replacing the host with one you control. This is where the user returns after authorizing.

When the app is created you get a Client ID and a Client Secret.

Copy the client secret now. It is shown only once. You can rotate it later from the app's detail page.

2. Send the user to authorize

Davi uses the authorization code flow with PKCE, so first generate a code_verifier and its S256 code_challenge:

CODE_VERIFIER=$(openssl rand -base64 48 | tr -d '=+/\n')
CODE_CHALLENGE=$(printf '%s' "$CODE_VERIFIER" | openssl dgst -sha256 -binary | openssl base64 | tr '+/' '-_' | tr -d '=\n')
echo "$CODE_CHALLENGE"

Keep CODE_VERIFIER for step 3. Now open the authorization endpoint in a browser, with the challenge in place of CODE_CHALLENGE:

GET https://davi.social/oauth/authorize
  ?response_type=code
  &client_id=YOUR_CLIENT_ID
  &redirect_uri=https://yourapp.com/callback
  &scope=openid profile
  &state=RANDOM_STATE
  &code_challenge=CODE_CHALLENGE
  &code_challenge_method=S256

Sign in and consent. Davi redirects to your redirect_uri with a short-lived code and the state you sent.

3. Exchange the code for tokens

Send the code and the code_verifier to the token endpoint, authenticating with your client ID and secret:

curl -X POST "https://api.davi.social/oauth2/token" \
  -u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=authorization_code" \
  -d "code=AUTHORIZATION_CODE" \
  -d "redirect_uri=https://yourapp.com/callback" \
  -d "code_verifier=CODE_VERIFIER"

The response holds your tokens:

{
  "access_token": "eyJhbGciOi...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "refresh_token": "def502...",
  "scope": "openid profile",
  "id_token": "eyJhbGciOi..."
}

4. Call the API

Send the access token as a bearer token. Fetch the signed-in user:

curl "https://api.davi.social/api/v1/users/me" \
  -H "Authorization: Bearer ACCESS_TOKEN"

The response is the account you signed in with. You have registered an app, signed in a Davi user, and made an authenticated request.

Where to go next