> For the complete documentation index, see [llms.txt](https://docs.petje.af/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.petje.af/petje.af-api/authentication.md).

# Authentication

The Petje.af API allows developers to use the OAuth2 protocol to allow a Petje.af user to grant a 3rd party application partial access to his/her account.

## Introduction

### 1. Registering your client application

Before integrating the Petje.af API, you’ll need to register a new OAuth2 application in your Petje.af dashboard.

![Go to "Koppelingen > Apps" for creating a client application](https://3983081690-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Lh9M5OcufDN8F3i6rFD%2Fuploads%2FJmYU83EXNnMzWoZRIcpf%2FScreenshot%202026-06-16%20at%2014.26.23.png?alt=media\&token=f71af6bd-5028-4e08-87b3-24ca8151ca76)

### **2. Redirect users to request access**

Redirect users form your application to [the authorize page](/petje.af-api/authentication/authorize.md) using the necessary scopes. On this page the user can grant authorization to your client application for [the scopes](/petje.af-api/authentication/scopes.md) you requested.

### 3. Petje.af redirects back to your site

If the user approves your application, Petje.af will redirect them back to your `redirect_uri` with a temporary `code` parameter.

Example of the redirect:

```
GET https://example.com/oauth/callback?code=CODE&state=STATE
```

### 4. **Exchange code for an access token**

After you have received the temporary code, you can exchange it for valid access and refresh tokens using t[he tokens endpoint](/petje.af-api/authentication/tokens.md).

### 5. Refreshing tokens

Because the Petje.af API issues short-lived access tokens, you will need to refresh access tokens using [the tokens endpoint](/petje.af-api/authentication/tokens.md) via the refresh token that was provided when the access token was issued.
