This step of the authorization flow requests the user to install and authorize your app. If the user is not signed in, the user is redirected to the sign-in page. After signing in, the user is redirected to a page where the user needs to install and authorize your app. After the user installs and authorizes your app, it will be redirected back to redirect_uri with the authorization code value.
To obtain authorization for your app:
- Send the request authorization link to the user.
For more information, see Create authorization request link.
- Request the user to open the request authorization link in their browser.
Using our earlier example, the user opens the following link in their browser:
The Install & authorize page appears in the user's browser.
- The user must click the Install & authorize button.
Miro redirects the user to the
redirect_uriprovided in your authorization request link. The redirect URI also
contains the following response data:
A temporary authorization code in the
codeparameter. The client app uses the authorization code to obtain an access token. The authorization code can only be used once and it expires 10 minutes after being issued. Note this code as you need it in the next step of the authorization flow.
If you provided a value for the
stateparameter in the authorization request link, the same state string is returned in the
Using our earlier example, the user is redirected to the following URI:
|Response parameter||Description||Sample value|
|URI of the page that loaded after the user provided the authorization.|
|Temporary authorization code that can be exchanged with an access token. The authorization code can only be used once and it expires 10 minutes after being issued. The client app uses the authorization code to obtain an access token. Note this code as you need it in the next step of the authorization flow.|
|The same |
|The Client ID of the app that is requesting for user authorization.|
|Team ID for the team where the app is being installed. As the app is authorized on a per-user basis, you must obtain authorization from each user.|