server | client

OAuth Test Server

Instructions for Use

This is a test server with a predefined static set of keys and tokens, you can make your requests using them to test your code (and mine ;)).

Your Consumer Key / Secret

Use this key and secret for all your requests.

Getting a Request Token

A successful request will return the following with new parameters returned in OAuth 2008.1:

oauth_token=requestkey&oauth_token_secret=requestsecret&oauth_expires_in=3600

An unsuccessful request will attempt to describe what went wrong using oauth_problem codes.

Example

http://api.mh-freya-game.com/oauth/example/request_token.php?oauth_version=1.0&oauth_nonce=5a9d7017614e95beff114cb3f956738a&oauth_timestamp=1752398106&oauth_consumer_key=key&oauth_signature_method=HMAC-SHA1&oauth_signature=lpE%2B%2FBTAhr%2FjFu1p1KKHrqqj3WE%3D

New in OAuth 2008.1

Getting an Access Token

The Request Token provided above is already authorized, you may use it to request an Access Token right away.

A successful request will return the following with new parameters returned in OAuth 2008.1:

oauth_token=accesskey&oauth_token_secret=accesssecret&oauth_session_handle=sessionhandle&oauth_expires_in=3600&oauth_authorization_expires_in=3600

An unsuccessful request will attempt to describe what went wrong.

Example

http://api.mh-freya-game.com/oauth/example/access_token.php?oauth_version=1.0&oauth_nonce=3c53a0cd47c7d11fcc4dd98c16f3c449&oauth_timestamp=1752398106&oauth_consumer_key=key&oauth_token=requestkey&oauth_signature_method=HMAC-SHA1&oauth_signature=%2Ft%2F5FDpPfLaOtP1BTiCmNYBKN2E%3D

New in OAuth 2008.1

New in OAuth 2008.1: Renewing an Access Token

A feature new in OAuth 2008.1 is access token renewal. When access tokens expire, you must acquire a new token using the renewal api.

A successful request will return the following:

oauth_token=accesskey&oauth_token_secret=accesssecret&oauth_session_handle=sessionhandle&oauth_expires_in=3600&oauth_authorization_expires_in=3600

An unsuccessful request will attempt to describe what went wrong.

Example

http://api.mh-freya-game.com/oauth/example/renew_access_token.php?oauth_version=1.0&oauth_nonce=4acbab80e27ee3b04999c0e7878a38c1&oauth_timestamp=1752398106&oauth_consumer_key=key&oauth_token=accesskey&oauth_session_handle=sessionhandle&oauth_signature_method=HMAC-SHA1&oauth_signature=FamxaTWgsSqNtPDlU6CrVe4%2FroU%3D

Making Authenticated Calls

Using your Access Token you can make authenticated calls.

A successful request will echo the non-OAuth parameters sent to it, for example:

method=foo&bar=baz

An unsuccessful request will attempt to describe what went wrong.

Example

http://api.mh-freya-game.com/oauth/example/echo_api.php?oauth_version=1.0&oauth_nonce=ae9a131b693ba5dc0e905b3f9888cf5d&oauth_timestamp=1752398106&oauth_consumer_key=key&method=foo%2520bar&bar=baz&oauth_token=accesskey&oauth_signature_method=HMAC-SHA1&oauth_signature=hqDBSV%2BLa8fR6cdSd6ca8ejQAmE%3D

Currently Supported Signature Methods

Current signing method is: HMAC-SHA1

Further Resources

There is also a test client implementation in here.

The code running this example can be downloaded from the PHP section of the OAuth google code project: http://code.google.com/p/oauth/