[{"data":1,"prerenderedAt":315},["ShallowReactive",2],{"navigation_docs_en":3,"-en-oauth-authorization-code-pkce":210,"-en-oauth-authorization-code-pkce-surround":310},[4,23,41,51,65,83,182,196],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":22},"Getting started","i-lucide-rocket","\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[10,14,18],{"title":11,"path":12,"stem":13},"Quick start","\u002Fen\u002Fgetting-started\u002Fquick-start","en\u002F1.getting-started\u002F1.quick-start",{"title":15,"path":16,"stem":17},"Trust model","\u002Fen\u002Fgetting-started\u002Ftrust-model","en\u002F1.getting-started\u002F2.trust-model",{"title":19,"path":20,"stem":21},"Enterprise integration journey","\u002Fen\u002Fgetting-started\u002Fenterprise-integration","en\u002F1.getting-started\u002F3.enterprise-integration",false,{"title":24,"icon":25,"path":26,"stem":27,"children":28,"page":22},"Storefront","i-lucide-store","\u002Fen\u002Fstorefront","en\u002F2.storefront",[29,33,37],{"title":30,"path":31,"stem":32},"Third-party Storefront","\u002Fen\u002Fstorefront\u002Fthird-party-storefront","en\u002F2.storefront\u002F1.third-party-storefront",{"title":34,"path":35,"stem":36},"Turnstile trust boundary","\u002Fen\u002Fstorefront\u002Fchallenge-and-turnstile","en\u002F2.storefront\u002F2.challenge-and-turnstile",{"title":38,"path":39,"stem":40},"Third-party Storefront public API","\u002Fen\u002Fstorefront\u002Fpublic-api","en\u002F2.storefront\u002F3.public-api",{"title":42,"icon":43,"path":44,"stem":45,"children":46,"page":22},"OAuth and identity","i-lucide-key-round","\u002Fen\u002Foauth","en\u002F3.oauth",[47],{"title":48,"path":49,"stem":50},"Third-party account authorization boundary","\u002Fen\u002Foauth\u002Fauthorization-code-pkce","en\u002F3.oauth\u002F1.authorization-code-pkce",{"title":52,"icon":53,"path":54,"stem":55,"children":56,"page":22},"Developer platform","i-lucide-blocks","\u002Fen\u002Fplatform","en\u002F4.platform",[57,61],{"title":58,"path":59,"stem":60},"Apps, versions, installations, and scopes","\u002Fen\u002Fplatform\u002Fapps-installations-scopes","en\u002F4.platform\u002F1.apps-installations-scopes",{"title":62,"path":63,"stem":64},"Origins, redirects, proxies, and environments","\u002Fen\u002Fplatform\u002Fsecurity-and-environments","en\u002F4.platform\u002F2.security-and-environments",{"title":66,"icon":67,"path":68,"stem":69,"children":70,"page":22},"Runtime extensions","i-lucide-workflow","\u002Fen\u002Fruntime","en\u002F5.runtime",[71,75,79],{"title":72,"path":73,"stem":74},"Installation Webhooks","\u002Fen\u002Fruntime\u002Fwebhooks","en\u002F5.runtime\u002F1.webhooks",{"title":76,"path":77,"stem":78},"Inventory synchronization","\u002Fen\u002Fruntime\u002Finventory-sync","en\u002F5.runtime\u002F2.inventory-sync",{"title":80,"path":81,"stem":82},"Automatic fulfillment providers","\u002Fen\u002Fruntime\u002Fauto-fulfillment","en\u002F5.runtime\u002F3.auto-fulfillment",{"title":84,"icon":85,"path":86,"stem":87,"children":88,"page":22},"API reference","i-lucide-braces","\u002Fen\u002Freference","en\u002F6.reference",[89,93,97],{"title":90,"path":91,"stem":92},"API Reference","\u002Fen\u002Freference\u002Fapi","en\u002F6.reference\u002F1.api",{"title":94,"path":95,"stem":96},"Errors, idempotency, and rate limits","\u002Fen\u002Freference\u002Ferrors-and-limits","en\u002F6.reference\u002F2.errors-and-limits",{"title":98,"path":99,"stem":100,"children":101,"page":22},"Endpoint catalog","\u002Fen\u002Freference\u002Foperations","en\u002F6.reference\u002F3.operations",[102,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178],{"title":103,"path":104,"stem":105},"Get the public runtime configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-runtime-config","en\u002F6.reference\u002F3.operations\u002F01.get-public-runtime-config",{"title":107,"path":108,"stem":109},"Get the public site bootstrap configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-bootstrap","en\u002F6.reference\u002F3.operations\u002F02.get-public-bootstrap",{"title":111,"path":112,"stem":113},"Get public contact channels","\u002Fen\u002Freference\u002Foperations\u002Fget-public-contact","en\u002F6.reference\u002F3.operations\u002F03.get-public-contact",{"title":115,"path":116,"stem":117},"List current published legal documents by locale","\u002Fen\u002Freference\u002Foperations\u002Flist-public-legal-documents","en\u002F6.reference\u002F3.operations\u002F04.list-public-legal-documents",{"title":119,"path":120,"stem":121},"Get the published Storefront decoration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-storefront-decoration","en\u002F6.reference\u002F3.operations\u002F05.get-public-storefront-decoration",{"title":123,"path":124,"stem":125},"Get the public store security configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-store-security-config","en\u002F6.reference\u002F3.operations\u002F06.get-public-store-security-config",{"title":127,"path":128,"stem":129},"Search public products","\u002Fen\u002Freference\u002Foperations\u002Fsearch-public-products","en\u002F6.reference\u002F3.operations\u002F07.search-public-products",{"title":131,"path":132,"stem":133},"List public categories","\u002Fen\u002Freference\u002Foperations\u002Flist-public-categories","en\u002F6.reference\u002F3.operations\u002F08.list-public-categories",{"title":135,"path":136,"stem":137},"Get the installation credential identity","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-identity","en\u002F6.reference\u002F3.operations\u002F09.get-installation-credential-identity",{"title":139,"path":140,"stem":141},"Get the installation credential readiness","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-readiness","en\u002F6.reference\u002F3.operations\u002F10.get-installation-credential-readiness",{"title":143,"path":144,"stem":145},"List the public product catalog","\u002Fen\u002Freference\u002Foperations\u002Flist-public-products","en\u002F6.reference\u002F3.operations\u002F11.list-public-products",{"title":147,"path":148,"stem":149},"Get a public product by slug","\u002Fen\u002Freference\u002Foperations\u002Fget-public-product","en\u002F6.reference\u002F3.operations\u002F12.get-public-product",{"title":151,"path":152,"stem":153},"Get a public store profile","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant","en\u002F6.reference\u002F3.operations\u002F13.get-public-merchant",{"title":155,"path":156,"stem":157},"List public products for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-products","en\u002F6.reference\u002F3.operations\u002F14.list-public-merchant-products",{"title":159,"path":160,"stem":161},"List public categories for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-categories","en\u002F6.reference\u002F3.operations\u002F15.list-public-merchant-categories",{"title":163,"path":164,"stem":165},"Get a public product for a store","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant-product","en\u002F6.reference\u002F3.operations\u002F16.get-public-merchant-product",{"title":167,"path":168,"stem":169},"Get the current API Key identity and scopes","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-identity","en\u002F6.reference\u002F3.operations\u002F17.get-api-key-identity",{"title":171,"path":172,"stem":173},"List public categories with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-categories","en\u002F6.reference\u002F3.operations\u002F18.list-api-key-catalog-categories",{"title":175,"path":176,"stem":177},"List public products with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-products","en\u002F6.reference\u002F3.operations\u002F19.list-api-key-catalog-products",{"title":179,"path":180,"stem":181},"Get a public product with an API Key","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-catalog-product","en\u002F6.reference\u002F3.operations\u002F20.get-api-key-catalog-product",{"title":183,"icon":184,"path":185,"stem":186,"children":187,"page":22},"Examples","i-lucide-code-xml","\u002Fen\u002Fexamples","en\u002F7.examples",[188,192],{"title":189,"path":190,"stem":191},"Minimal Nuxt Storefront","\u002Fen\u002Fexamples\u002Fnuxt-storefront","en\u002F7.examples\u002F1.nuxt-storefront",{"title":193,"path":194,"stem":195},"Webhook verification","\u002Fen\u002Fexamples\u002Fwebhook-verification","en\u002F7.examples\u002F2.webhook-verification",{"title":197,"icon":198,"path":199,"stem":200,"children":201,"page":22},"Versions and support","i-lucide-life-buoy","\u002Fen\u002Foperations","en\u002F8.operations",[202,206],{"title":203,"path":204,"stem":205},"Versions, migrations, and changelog","\u002Fen\u002Foperations\u002Fversions-and-migrations","en\u002F8.operations\u002F1.versions-and-migrations",{"title":207,"path":208,"stem":209},"Support and security disclosure","\u002Fen\u002Foperations\u002Fsupport-and-security","en\u002F8.operations\u002F2.support-and-security",{"id":211,"title":48,"body":212,"description":300,"extension":301,"links":302,"meta":303,"navigation":307,"path":49,"seo":308,"stem":50,"__hash__":309},"docs_en\u002Fen\u002F3.oauth\u002F1.authorization-code-pkce.md",{"type":213,"value":214,"toc":294},"minimark",[215,219,226,250,255,258,279,283,286],[216,217,48],"h1",{"id":218},"third-party-account-authorization-boundary",[220,221,222],"blockquote",{},[223,224,225],"p",{},"Status: the security boundary is public. OAuth endpoints, token schemas, DPoP, and refresh-token rotation have not passed the API security review, so this page provides no endpoint, curl command, or token-exchange example.",[223,227,228,229,233,234,237,238,241,242,245,246,249],{},"Users enter their email, password, and MFA only on the official Ayalink authorization domain. A third party must not proxy, embed, or imitate the Ayalink sign-in page, collect account factors, or receive or forward the Ayalink global-session Cookie. Third-party authorization is limited to Authorization Code with PKCE: every attempt uses high-entropy ",[230,231,232],"code",{},"state",", ",[230,235,236],{},"nonce",", and ",[230,239,240],{},"code_verifier",", only ",[230,243,244],{},"S256",", and an exactly registered HTTPS ",[230,247,248],{},"redirect_uri",".",[251,252,254],"h2",{"id":253},"a-session-is-not-a-grant","A session is not a grant",[223,256,257],{},"The Ayalink global session serves Ayalink-owned domains only. A third-party app grant is separate, minimal, and revocable. It is constrained to a specific app, installation, store\u002Fresource, audience, and user-approved scopes. It cannot become a platform session or prove ownership of another store or resource.",[223,259,260,261,233,264,267,268,233,271,274,275,278],{},"Do not put access tokens, refresh tokens, authorization codes, or verifiers in URLs, ",[230,262,263],{},"localStorage",[230,265,266],{},"sessionStorage",", IndexedDB, analytics, logs, error reports, support tickets, or recordings. For a durable session, use a same-origin BFF. The BFF stores only its own app grant and gives its frontend an ",[230,269,270],{},"HttpOnly",[230,272,273],{},"Secure",", appropriately ",[230,276,277],{},"SameSite"," application-session Cookie. It never forwards an Ayalink Cookie and never asks for an Ayalink password or MFA.",[251,280,282],{"id":281},"phishing-warning-and-recovery","Phishing warning and recovery",[223,284,285],{},"A malicious proxy can copy the page appearance, use a look-alike domain, terminate TLS, inject scripts, and record every input. Before authorizing, check the official authorization domain in the browser address bar. Never enter Ayalink credentials through chat, email, or a third-party page. If compromise is suspected, close the page, revoke the affected app\u002Finstallation grant from an official entry point, sign out of Ayalink sessions, update the password and reconfigure MFA, then report through the official security channel. Never send a token, Cookie, or verification code to a third party.",[223,287,288,289,293],{},"DPoP, refresh-token rotation, token-family replay detection, and the user grant-management entry point are currently ",[290,291,292],"strong",{},"unavailable\u002Fpending review",". Do not design a production dependency around them. API Reference remains at zero OAuth endpoints until the API publishes a security-reviewed public-only artifact.",{"title":295,"searchDepth":296,"depth":296,"links":297},"",2,[298,299],{"id":253,"depth":296,"text":254},{"id":281,"depth":296,"text":282},"Use the official authorization domain, PKCE S256, and isolated app grants without exposing account credentials to a proxy.","md",null,{"sourceGuide":304,"sourceHash":305,"sourceLocale":306},"oauth-developer-guide","b0c5e9b7dbff3d903c5b6ebccc42873e965852e9eafb8804570c40440a829ee9","en",true,{"title":48,"description":300},"e69wvTjz2L_xo41w5zjPqiYlafXMUckLyra5Hd7ZBBI",[311,313],{"title":38,"path":39,"stem":40,"description":312,"children":-1},"The Storefront public API entry generated from the authoritative public-only artifact.",{"title":58,"path":59,"stem":60,"description":314,"children":-1},"Model immutable app versions and store-bound installations with least-privilege scopes.",1785955320477]