VPNDetectionVPNDetection

Authorize

GET
/oauth/authorize

The browser entry point for the authorization-code flow. This is a redirect target, not something to call from code.

Any client may sign in without registering first by using a Client ID Metadata Document: make client_id an https URL that serves your client's metadata as JSON, naming that same URL as its client_id, with token_endpoint_auth_method none and your redirect_uris. An https redirect URI must be on the same origin as the client_id; a loopback one (http://127.0.0.1, http://[::1], http://localhost) matches on any port. Such a client is granted apikeys.use at most.

An unknown client_id or an unregistered redirect_uri is shown to the USER and never redirected, because sending an error to an address we have not verified belongs to you is how an open redirector works. Everything else comes back to your redirect_uri with error, your state, and iss.

Query Parameters

client_id*string
redirect_uri*string
response_type*string
Value in"code"
code_challenge*string
code_challenge_method*string

S256, named explicitly. plain, or no method at all, is refused rather than downgraded.

Value in"S256"
scope?string
state?string

Returned unchanged. Use it to bind the response to your request.

resource?string

RFC 8707. What the token is FOR, so it cannot be replayed elsewhere: this brand's MCP server, the only resource it issues tokens for. Anything else answers invalid_target. A client that names none is given that server.

Response Body

curl -X GET "https://api.vpndetection.io/oauth/authorize?client_id=string&redirect_uri=string&response_type=code&code_challenge=string&code_challenge_method=S256"
Empty
Empty
Empty