HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulehoauth2-2.14.3Haskell2010

Network.OAuth.OAuth2.TokenRequest

Bindings Access Token and Refresh Token part of The OAuth 2.0 Authorization Framework RFC6749 https://www.rfc-editor.org/rfc/rfc6749

  • 2 types
  • 19 values
  • Packagehoauth2-2.14.3
  • Exports21
  • LanguageHaskell2010
  • LicenceMIT
  • SourceTokenRequest.hs

Token Request Errors

3 declarations
Instances3Eq, Show, FromJSON

URL

2 declarations
valueaccessTokenUrl
  1. :: OAuth2
  2. -> ExchangeToken

    access code gained via authorization URL

  3. -> (URI, PostBody)

    access token request URL plus the request body.

#

Prepare the URL and the request body query for fetching an access token.

Token management

8 declarations
valuefetchAccessTokenWithAuthMethod
  1. :: MonadIO m
  2. => ClientAuthenticationMethod
  3. -> Manager

    HTTP connection manager

  4. -> OAuth2

    OAuth Data

  5. -> ExchangeToken

    Authorization Code

  6. -> ExceptT TokenResponseError m OAuth2Token

    Access Token

#

Exchange code for an Access Token

OAuth2 spec allows credential (client_id, client_secret) to be sent either in the header (a.k.a ClientSecretBasic). or as form/url params (a.k.a ClientSecretPost).

The OAuth provider can choose to implement only one, or both. Look for API document from the OAuth provider you're dealing with. If you`re uncertain, try fetchAccessToken which sends credential in authorization http header, which is common case.

valuerefreshAccessTokenWithAuthMethod
  1. :: MonadIO m
  2. => ClientAuthenticationMethod
  3. -> Manager

    HTTP connection manager.

  4. -> OAuth2

    OAuth context

  5. -> RefreshToken

    Refresh Token gained after authorization

  6. -> ExceptT TokenResponseError m OAuth2Token
#

Fetch a new AccessToken using the Refresh Token.

OAuth2 spec allows credential ("client_id", "client_secret") to be sent either in the header (a.k.a ClientSecretBasic). or as form/url params (a.k.a ClientSecretPost).

The OAuth provider can choose to implement only one, or both. Look for API document from the OAuth provider you're dealing with. If you're uncertain, try refreshAccessToken which sends credential in authorization http header, which is common case.

Utilies

8 declarations