Shoonya's OAuth login is a 4-step redirect-and-exchange flow. Your application never sees the user's password — Noren's own hosted login page collects credentials, and your backend only ever handles a short-lived authorization code and the resulting access token.
Flow diagram
Step-by-step
Step
Direction
Params
Details
1
Third-party app → Noren login
client_id
Redirect the user's browser to the OAuth authorize URL.
2
Noren login → Third-party app
code
After the user logs in, Noren redirects back with a short-lived authorization code.
3
Third-party app server → Noren server
code, checksum
Server-to-server POST to GenAcsTok, exchanging the code for an access token.
4
Noren server → Third-party app server
access_token
The access token is returned and used as the Bearer token for all subsequent API calls.
Overview
Shoonya's OAuth login is a 4-step redirect-and-exchange flow. Your application never sees the user's password — Noren's own hosted login page collects credentials, and your backend only ever handles a short-lived authorization code and the resulting access token.
Flow diagram
Step-by-step
client_idcodecode,checksumGenAcsTok, exchanging the code for an access token.access_tokenBearertoken for all subsequent API calls.Related
See Manual Login (OAuth) for the full request/response payloads and the checksum calculator, and For Vendors / Partners for the vendor-specific variant of step 1.