Authenticating with OAuth
The Manob.Ai Market API supports the full OAuth authentication flow, so that you can allow users of your app to sign in with their Manob.Ai Account in order to access the API on their behalf. Using OAuth authentication is simple:
First, register your application so that users know which permissions your app needs. Make a note of the secret application key, and OAuth client ID, that you'll be given during registration – they'll come in handy.
Before your app accesses the Manob.Ai API, you'll need to authenticate the user. Your app should redirect the user to the following location:
https://api.manob.ai/authorization?response_type=code&client_id=[CLIENT ID]&redirect_uri=[REDIRECT URI]
You can replace [CLIENT_ID] with the OAuth Client ID of your app from the My Apps page, and [REDIRECT_URI] with the fully-qualified URL you'd like to send the user back to once authentica tion is successful (this must match the Confirmation URL setting configured when you created your app – you can edit it from the above page).
After the user has logged in and given their permission, the Manob.Ai API will
redirect them back to your application on the Confirmation URL provided,
with a single-use authentication code provided in the query string
(eg. http://your.app/callback?code=abc123...). You must use this code to
request an access token from the API, by sending the following POST request
from your server (encoded as application/x-www-form-urlencoded), replacing
[CODE] with the code you've just received, [CLIENT_SECRET] with your secret
application key, and the other fields as necessary:
https://manob.ai/oauth/callback?code=1234567890abcdef.
The server will respond with an access token:
{
"refresh_token": "GBdxWsxo1CqAK9yCneH75wgkXw1q7bio",
"token_type": "bearer",
"access_token": "c0lQ2WLYW9qAZ9RH12cH1fJPzVWSscXP",
"expires_in": 3600
}
You can use the access token, which is valid for up to an hour, to make requests to the API on behalf of the logged-in user, by adding it as a bearer token to the Authorization header on any subsequent requests:
curl -H "Authorization: Bearer c0lQ2WLYW9qAZ9RH12cH1fJPzVWSscXP" https://api.manob.ai/v1/market/private/user/account.json
{
"account": {
"image": "https://0.s3.manob.ai/files/100000009/0006893824_192.jpg",
"firstname": "Test",
"surname": "User",
"available_earnings": "0.00",
"total_deposits": "0.00",
"balance": "0.00",
"country": "Australia"
}
}
After the one-hour period is up and the access token has expired, you can continue using the API on the user's behalf with the refresh token that was originally returned. You can use the refresh token to request a new, valid access token with the request below, and then use it for subsequent requests to the API:
{
"token_type": "bearer",
"access_token": "x0lQ2WLYW9qAZ9RH12cH1fJPzVWSscXZ",
"expires_in": 3600
}
Note: the Manob.Ai API also supports the alternate, implicit OAuth authentication flow, if you are developing a browser-based app and don't wish to include the application's secret key in a place where it could be read by users.
Authenticating with a Personal Token
It may be that your app doesn't require to assume the role of a third-party user to access the Manob.Ai API - for example, if your app just accesses public data, such as performing searches for items on Manob.Ai Market. In this situation, rather than the complication of implementing OAuth and requiring users to log in and grant permissions to your app, you can simply generate a personal token, and then insert it directly into the authorization header on any API requests:
curl -H "Authorization: Bearer oVi4yPxk1bJ64Y2qOsLJ2D2ZlC3FpK4L" https://api.manob.ai/v1/market/total-items.json
{
"total-items": {
"total_items": "7411418"
}
}