Interactive OAuth login flow — redirect the user to Shoonya, capture the authorization code, and exchange it for an access token.
Overview
This is the standard 3-step OAuth flow for individual users logging in interactively (as opposed to a headless/vendor integration — see For Vendors / Partners for that variant). The user authenticates directly on Shoonya's own login page — your application never sees their password.
PrerequisiteYour Client ID's IP address must already be whitelisted and you'll need the Secret Code before step 3 below works — see IP Whitelisting Guide if you haven't done this yet.
Step 1 — Redirect to OAuth URL
Send the user's browser to the authorize endpoint with your app's client_id:
Replace Your_Client_id with your client id . The user lands on Shoonya's hosted login page and enters their User ID, Password, and OTP/TOTP.
Step 2 — Receive the authorization code
After successful login, Shoonya redirects back to your registered redirect URL with an authorization code appended as a query parameter. Capture this code — it's short-lived and can only be exchanged once.
Step 3 — Exchange code for access token
Call GenAcsTok with the authorization code and a checksum, to receive the access token used for all subsequent API calls.
Method
POST
URL
https://api.shoonya.com/NorenWClientAPI/GenAcsTok
Content-Type
text/plain
Payload
jData=<JSON payload>
Field
Type
Required
Description
code
string
Yes
The authorization code received in Step 2.
checksum
string
Yes
SHA256(client_id + secret_key + auth_code) — see calculator below.
bash
curl-X POST https://api.shoonya.com/NorenWClientAPI/GenAcsTok \
-H"Content-Type: text/plain" \
-d'jData={"code":"<auth_code>","checksum":"<sha256_hex>"}'
Overview
This is the standard 3-step OAuth flow for individual users logging in interactively (as opposed to a headless/vendor integration — see For Vendors / Partners for that variant). The user authenticates directly on Shoonya's own login page — your application never sees their password.
Step 1 — Redirect to OAuth URL
Send the user's browser to the authorize endpoint with your app's
client_id:Replace
Your_Client_idwith your client id . The user lands on Shoonya's hosted login page and enters their User ID, Password, and OTP/TOTP.Step 2 — Receive the authorization code
After successful login, Shoonya redirects back to your registered redirect URL with an authorization
codeappended as a query parameter. Capture this code — it's short-lived and can only be exchanged once.Step 3 — Exchange code for access token
Call
GenAcsTokwith the authorization code and a checksum, to receive the access token used for all subsequent API calls.POSThttps://api.shoonya.com/NorenWClientAPI/GenAcsToktext/plainjData=<JSON payload>codechecksumSHA256(client_id + secret_key + auth_code)— see calculator below.Response
Use
AccessTokenas theBearertoken in theAuthorizationheader for all subsequent calls — see API Structure.Checksum calculator
This calculator runs entirely in the browser — nothing is sent to a server.
Related
See Token Renewal for refreshing an expired token without a full re-login, and Logout for invalidating the token when done.