Skip to Main Content

Manual Login (OAuth)

Interactive OAuth login flow — redirect the user to Shoonya, capture the authorization code, and exchange it for an access token.

Overview

This is the standard 3-step OAuth flow for individual users logging in interactively (as opposed to a headless/vendor integration — see For Vendors / Partners for that variant). The user authenticates directly on Shoonya's own login page — your application never sees their password.

PrerequisiteYour Client ID's IP address must already be whitelisted and you'll need the Secret Code before step 3 below works — see IP Whitelisting Guide if you haven't done this yet.

Step 1 — Redirect to OAuth URL

Send the user's browser to the authorize endpoint with your app's client_id:

text
https://api.shoonya.com/OAuthlogin/authorize/oauth?client_id=Your_Client_id

Replace Your_Client_id with your client id . The user lands on Shoonya's hosted login page and enters their User ID, Password, and OTP/TOTP.

Step 2 — Receive the authorization code

After successful login, Shoonya redirects back to your registered redirect URL with an authorization code appended as a query parameter. Capture this code — it's short-lived and can only be exchanged once.

Step 3 — Exchange code for access token

Call GenAcsTok with the authorization code and a checksum, to receive the access token used for all subsequent API calls.

MethodPOST
URLhttps://api.shoonya.com/NorenWClientAPI/GenAcsTok
Content-Typetext/plain
PayloadjData=<JSON payload>
FieldTypeRequiredDescription
codestringYesThe authorization code received in Step 2.
checksumstringYesSHA256(client_id + secret_key + auth_code) — see calculator below.
bash
curl -X POST https://api.shoonya.com/NorenWClientAPI/GenAcsTok \
  -H "Content-Type: text/plain" \
  -d 'jData={"code":"<auth_code>","checksum":"<sha256_hex>"}'

Response

json
{
  "stat": "Ok",
  "susertoken": "<AccessToken>",
  "uid": "ABC1234",
  "actid": "ABC1234"
}

Use AccessToken as the Bearer token in the Authorization header for all subsequent calls — see API Structure.

Checksum calculator

This calculator runs entirely in the browser — nothing is sent to a server.

See Token Renewal for refreshing an expired token without a full re-login, and Logout for invalidating the token when done.