The last step of signing in: the app trades the one-time code from the browser for the account email, an API key of this phone's own and the plan limits.
01 · The call
POST https://opensolr.com/app/tokenOnce per sign-in, right after the browser hands the code back to the app. See signing in.
A JSON body with:
grant_typeauthorization_code, thecodeand thecode_verifierthe app kept;client_idopensolr-photosandredirect_urihttps://opensolr.com/app/callback, which must match exactly;device_id,device_label(such as Google Pixel 8) andapp_version, so the phone gets a key of its own and shows in Account › Devices.
02 · The answer
{"status": true, "email": "…", "api_key": "…", "key_kind": "device", "account": {…plan limits…}}
key_kindisdevice: the key belongs to this phone only and can be signed out on its own.- The code works once and for 60 seconds; the server marks it used in one atomic step, checks the verifier against the challenge, and checks the account is active.
- It allows 20 attempts a minute per address, and every refusal looks the same. The app then asks you to tap Sign in again.