app/token

The last step of signing in: the one-time code traded for this phone's own key.

The last step of signing in: the app trades the one-time code from the browser for the account email, an API key of this phone's own and the plan limits.

01 · The call
POST https://opensolr.com/app/token

Once per sign-in, right after the browser hands the code back to the app. See signing in.

A JSON body with:

  • grant_type authorization_code, the code and the code_verifier the app kept;
  • client_id opensolr-photos and redirect_uri https://opensolr.com/app/callback, which must match exactly;
  • device_id, device_label (such as Google Pixel 8) and app_version, so the phone gets a key of its own and shows in Account › Devices.
02 · The answer
{"status": true, "email": "…", "api_key": "…", "key_kind": "device", "account": {…plan limits…}}
  • key_kind is device: the key belongs to this phone only and can be signed out on its own.
  • The code works once and for 60 seconds; the server marks it used in one atomic step, checks the verifier against the challenge, and checks the account is active.
  • It allows 20 attempts a minute per address, and every refusal looks the same. The app then asks you to tap Sign in again.

Every call it makes

Opensolr Photos is open source and MIT licensed. Questions about your Opensolr account, index or plan go to opensolr.com/contact; questions about the app itself belong on GitHub.

Opensolr Photos Documentation