In this tutorial you register a server-side app, sign in a Davi user with it,
and use their token to fetch their account from the API. The API is served under
https://api.davi.social/api/v1 and every request carries an OAuth 2.0
bearer token.
You need a Davi account that owns or manages an organization, because apps are registered per organization, and access to the Davi dashboard.
1. Register an app
In the dashboard, open your organization and go to Developer → Apps → Create
app. Choose Server-side application. This is a confidential client: it
receives a client_secret.
Add the redirect URI https://yourapp.com/callback, replacing the host with one
you control. This is where the user returns after authorizing.
When the app is created you get a Client ID and a Client Secret.
Copy the client secret now. It is shown only once. You can rotate it later from the app's detail page.
2. Send the user to authorize
Davi uses the authorization code flow with PKCE, so first generate a
code_verifier and its S256 code_challenge:
CODE_VERIFIER=$(openssl rand -base64 48 | tr -d '=+/\n')
CODE_CHALLENGE=$(printf '%s' "$CODE_VERIFIER" | openssl dgst -sha256 -binary | openssl base64 | tr '+/' '-_' | tr -d '=\n')
echo "$CODE_CHALLENGE"
Keep CODE_VERIFIER for step 3. Now open the authorization endpoint in a
browser, with the challenge in place of CODE_CHALLENGE:
GET https://davi.social/oauth/authorize
?response_type=code
&client_id=YOUR_CLIENT_ID
&redirect_uri=https://yourapp.com/callback
&scope=openid profile
&state=RANDOM_STATE
&code_challenge=CODE_CHALLENGE
&code_challenge_method=S256
Sign in and consent. Davi redirects to your redirect_uri with a short-lived
code and the state you sent.
3. Exchange the code for tokens
Send the code and the code_verifier to the token endpoint, authenticating
with your client ID and secret:
curl -X POST "https://api.davi.social/oauth2/token" \
-u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=authorization_code" \
-d "code=AUTHORIZATION_CODE" \
-d "redirect_uri=https://yourapp.com/callback" \
-d "code_verifier=CODE_VERIFIER"
The response holds your tokens:
{
"access_token": "eyJhbGciOi...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "def502...",
"scope": "openid profile",
"id_token": "eyJhbGciOi..."
}
4. Call the API
Send the access token as a bearer token. Fetch the signed-in user:
curl "https://api.davi.social/api/v1/users/me" \
-H "Authorization: Bearer ACCESS_TOKEN"
The response is the account you signed in with. You have registered an app, signed in a Davi user, and made an authenticated request.
Where to go next
- Sign-in: the full flow, including public
clients and the
login_requiredandconsent_requiredresponses. - Authentication Model: the OAuth 2.0 / OIDC model and every grant type.
- Acting as an Organization: act on behalf of an organization, which webhooks and org resources require.
- Making Requests: pagination, errors, and rate limits.