OAuth 2.1

Yetkilendir

Kullanıcıyı onay ekranına götürür (oturum yoksa önce giriş). Onaylanınca redirect_uri?code=…&state=… adresine döner; reddedilirse error=access_denied. PKCE (S256) zorunludur.

GET/oauth/authorize

Yetkilendirme

Kimlik doğrulama gerekmez.

Sorgu parametreleri

response_typestringzorunlu
Yalnız code.
Değerlercode
client_idstringzorunlu
Kayıtta alınan kimlik ya da CIMD adresi.
redirect_uristringzorunlu
Kayıtlı dönüş adresi.
scopestringisteğe bağlı
crm.read crm.write (ve isteğe bağlı offline_access). Boşsa ikisi birden.
statestringisteğe bağlı
İstemcinin CSRF değeri (aynen döner).
code_challengestringzorunlu
BASE64URL(SHA256(code_verifier)).
code_challenge_methodstringzorunlu
Yalnız S256.
DeğerlerS256
resourcestringisteğe bağlı
MCP kaynağı (https://<kurulum>/mcp) — REST için boş bırakın.
İstek
https://ornek.solk.app/oauth/authorize?response_type=code&client_id=crm_Jq8w…&redirect_uri=https%3A%2F%2Fuygulamaniz.com%2Foauth%2Fcallback&scope=crm.read%20crm.write&state=xyz123&code_challenge=E9Melhoa2Owv…&code_challenge_method=S256
Yanıt
HTTP/1.1 302 Found
Location: https://uygulamaniz.com/oauth/callback?code=Zx8…&state=xyz123