Skip to Main Content

Login Flow Overview

The end-to-end OAuth handshake — redirect, authorization code, checksum-verified token exchange.

Overview

Shoonya's OAuth login is a 4-step redirect-and-exchange flow. Your application never sees the user's password — Noren's own hosted login page collects credentials, and your backend only ever handles a short-lived authorization code and the resulting access token.

Flow diagram

Shoonya OAuth login flow Four-step diagram: the third-party app redirects to Noren login, receives an auth code, exchanges it for an access token via a checksum-protected POST, and gets the access token back. Third-party app Client Noren login OAuth screen Third-party app server Backend Noren server GenAcsTok 1. Redirect · client_id 2. Redirect back · code 3. POST · code, checksum 4. access_token

Step-by-step

StepDirectionParamsDetails
1Third-party app → Noren loginclient_idRedirect the user's browser to the OAuth authorize URL.
2Noren login → Third-party appcodeAfter the user logs in, Noren redirects back with a short-lived authorization code.
3Third-party app server → Noren servercode, checksumServer-to-server POST to GenAcsTok, exchanging the code for an access token.
4Noren server → Third-party app serveraccess_tokenThe access token is returned and used as the Bearer token for all subsequent API calls.

See Manual Login (OAuth) for the full request/response payloads and the checksum calculator, and For Vendors / Partners for the vendor-specific variant of step 1.