photon account oauth.
Browse the automatic command reference.
Clients
--redirect-uri and --scope are repeatable; without --scope the client has
no delegated scopes. The default redirect must exactly match one of the
supplied redirect URIs. Redirect URIs must use HTTPS, except for HTTP loopback
URLs during development. User info, fragments, duplicates, and more than ten
redirect URIs are rejected before the request is sent.
Creation sends an idempotency key, generated unless you pass
--idempotency-key. If the outcome is uncertain — the connection dropped or
Photon answered with a server error — the error names the key: retry the same
command with it rather than a new one, and Photon returns the client the first
request created.
update replaces redirect URIs or scopes when you supply them. Use
--clear-description or --clear-scopes to remove those values:
delete reports status. When Photon has accepted the deletion but provider
cleanup is still pending, the CLI warns that existing tokens may keep working
until it completes.
Test an authorization
authorize builds an authorization-code request and opens it, which is the
fastest way to check a client’s redirect URIs and scopes:
This helper only generates the authorization URL, state, and nonce. Your
registered application handles the callback and exchanges the code with its
own client secret — the CLI never accepts or stores that secret.
Secrets
secret list returns metadata only, including revokesAt for a secret whose
revocation is scheduled.
These commands replaced
photon account oauth client and
photon account oauth secret, which now only point here.