Allyable Provider for OAuth 2.0 Client

This package provides Allyable OAuth 2.0 support for the PHP League's OAuth 2.0 Client.


To install, use composer:

composer require nathanhennig/oauth2-allyable


Usage is the same as The League's OAuth client, using \Nathanhennig\OAuth2\Client\Provider\Allyable as the provider.

Authorization Code Flow

$provider = new Nathanhennig\OAuth2\Client\Provider\Allyable([
    'clientId'          => '{allyable-client-id}',
    'clientSecret'      => '{allyable-client-secret}',
    'redirectUri'       => ''

if (!isset($_GET['code'])) {

    // If we don't have an authorization code then get one
    $authUrl = $provider->getAuthorizationUrl();
    $_SESSION['oauth2state'] = $provider->getState();
    header('Location: '.$authUrl);

// Check given state against previously stored one to mitigate CSRF attack
} elseif (empty($_GET['state']) || ($_GET['state'] !== $_SESSION['oauth2state'])) {

    exit('Invalid state');

} else {

    // Try to get an access token (using the authorization code grant)
    $token = $provider->getAccessToken('authorization_code', [
        'code' => $_GET['code']

    // Optional: Now you have a token you can look up a users profile data
    try {

        // We got an access token, let's now get the user's details
        $user = $provider->getResourceOwner($token);

        // Use these details to create a new profile
        printf('Hello %s!', $user->getId());

    } catch (Exception $e) {

        // Failed to get user details
        exit('Oh dear...');

    // Use this to interact with an API on the users behalf
    echo $token->getToken();

Authorization flow example - Temporary Section

  1. Put the url to the browser address string.<client_id>&client_secret=<client_secret>&redirect_uri=<redirect_url>&scope=openid%20profile%20email%20phone%20offline_access&response_type=code&state=<random_string>

  1. Do the sign in and after that page should be redirected to the redirect url specified in configuration. image.png Here the code and state parameter are interesting for us. Code is the authorization code, it is used for getting refresh token. State is some random string which was provided on previous step and client can use it to validate that redirect was correct - state on first step and second step should be equal. State is optional parameter.

  2. Get the refresh token by authorization code

curl --location --request POST '' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=allyacademy' \
--data-urlencode 'client_secret=3d9e0eece8e368b7103fde7ad5cbff58' \
--data-urlencode 'code=<your_code>' \
--data-urlencode 'grant_type=authorization_code' \
--data-urlencode 'redirect_uri=https://localhost:8000/home'

Response contains:

  • "id_token" - can be used for logout
  • "refresh_token" - is needed to get new access_token after it is expired.
  • "access_token" - token to authorize in our system, in case with sso - to get user information
  1. Get the user information
curl --location --request GET '' \
--header 'Authorization: Bearer 84A936F1116A4BB504D25C4F0256772294EAA5EA9595B353DE8F796AD5A8A08B'
  1. Renew the access token using refresh token
curl --location --request POST '' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'refresh_token=4BA310123A6B554E239E49F493070F546D087520AFFAFEAC80D7DF3C2C30524F' \
--data-urlencode 'grant_type=refresh_token' \
--data-urlencode 'client_id=allyacademy' \
--data-urlencode 'client_secret=3d9e0eece8e368b7103fde7ad5cbff58'
  1. Logout Put to the browser address string.

Endpoints - Temporary Section

  1. Authorize
curl --location --request GET 'https:/
&state=<some_random_string (optional)>'
  1. Refresh Token
curl --location --request POST '' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=<client_id>' \
--data-urlencode 'client_secret=<client_secret>' \
--data-urlencode 'code=<authorization_code>' \
--data-urlencode 'grant_type=authorization_code' \
--data-urlencode 'redirect_uri=<redirect_url>'
  1. Access token
curl --location --request POST '' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=<client_id>' \
--data-urlencode 'client_secret=<client_secret>' \
--data-urlencode 'refresh_token=<refresh_token>' \
--data-urlencode 'grant_type=refresh_token'
  1. User information
curl --location --request GET '' \
--header 'Authorization: Bearer <access_token>'
  1. Logout
curl --location --request GET '
&state=<some_random_string (optional)>'


$ ./vendor/bin/phpunit


Please see CONTRIBUTING for details.


