## Authorize user app with and without PKCE

### cURL

```
curl --request GET \
  --url https://yourcompany.login.fabric.inc/oauth2/default/v1/authorize
```

```
import requests

url = "https://yourcompany.login.fabric.inc/oauth2/default/v1/authorize"

response = requests.get(url)

print(response.text)
```

```
const options = {method: 'GET'};

fetch('https://yourcompany.login.fabric.inc/oauth2/default/v1/authorize', options)
  .then(res => res.json())
  .then(res => console.log(res))
  .catch(err => console.error(err));
```

```
<?php

$curl = curl_init();

curl_setopt_array($curl, [\
  CURLOPT_URL => "https://yourcompany.login.fabric.inc/oauth2/default/v1/authorize",\
  CURLOPT_RETURNTRANSFER => true,\
  CURLOPT_ENCODING => "",\
  CURLOPT_MAXREDIRS => 10,\
  CURLOPT_TIMEOUT => 30,\
  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\
  CURLOPT_CUSTOMREQUEST => "GET",\
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
  echo "cURL Error #:" . $err;
} else {
  echo $response;
}
```

```
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

url := "https://yourcompany.login.fabric.inc/oauth2/default/v1/authorize"

req, _ := http.NewRequest("GET", url, nil)

res, _ := http.DefaultClient.Do(req)

defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

fmt.Println(string(body))

}
```

```
HttpResponse<String> response = Unirest.get("https://yourcompany.login.fabric.inc/oauth2/default/v1/authorize")
  .asString();
```

```
require 'uri'
require 'net/http'

url = URI("https://yourcompany.login.fabric.inc/oauth2/default/v1/authorize")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)

response = http.request(request)
puts response.read_body
```

### Query Parameters

- **client_id**  
  *string*  
  Required: Client ID of the user app

- **response_type**  
  *string*  
  Required: Type of the response expected. This should always be set to `code` (as per OAuth 2.0 grant type, refer to [RFC 6749](https://datatracker.ietf.org/doc/html/rfc6749#page-19)) for additional info.

- **scope**  
  *string*  
  Required: Scope of the endpoint call. This should always be set to `openid` (as per OpenID Connect standard. Refer to [OpenID Connect](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest) for additional info)

- **redirect_uri**  
  *string*  
  Required: Redirect URI of the user app is where fabric Identity will redirect the user upon successful login. This URI should be hosted by the user app. As part of the redirect, you will receive the auth code (as `code` query parameter) which can then be exchanged for the access token (refer to `/token`).

- **state**  
  *string*  
  Required: Random string created by the user app. It's used to maintain state between the request and the callback. The `state` helps mitigate Cross-Site Request Forgery (CSRF) when it's cryptographically derived from a browser cookie that signifies the user or session.

- **code_challenge_method**  
  *string*  
  Required only when using authorization code flow with PKCE. A code challenge method supported by PKCE specification. fabric Identity only supports the value of `S256` (Refer to [RFC 7636](https://datatracker.ietf.org/doc/html/rfc7636#section-4.2) for additional info). This parameter is mandatory for authorization code flow with PKCE and isn't required for the regular authorization code flow.

- **code_challenge**  
  *string*  
  Required only when using authorization code flow with PKCE. The code challenge created by the user app as per the specification on PKCE - [RFC 7636](https://datatracker.ietf.org/doc/html/rfc7636#section-4.2).

### Response

**302**  
Found. A successful response to this endpoint will re-direct the user to the hosted Login page provided by the fabric Identity. Once the user successfully logs in, fabric Identity would re-direct the client back to the `redirect_uri` hosted on the user app with the authorization code (as query parameter `code`) and the state (as query parameter `state`). The `state` parameter in the callback would be the same value as sent in the request.
