The standard
Drime implements OAuth 2.0 with the authorization code grant and PKCE (RFC 6749, RFC 7636, and RFC 8252 for native apps). A standard OAuth 2 client library works as is.
These URLs carry no version number: only the data API is versioned (
/api/v1). Point a generic client at the discovery URL and it configures itself.
Drime does not implement OpenID Connect: there is no ID token and no userinfo endpoint. To know who authorized your application, call GET /users/me with their token.
Create an application
Open the developer console, click Create application and answer:- Name: what your users see on the authorization screen. A name with the word “Drime” or “official” in it is refused, so that nobody can pass for Drime itself.
- What are you building?
- A website or a server: a confidential client. You get a secret key, to keep on your server.
- A desktop or mobile app: a public client. No secret key, and PKCE is required.
- A script, just for me: a public client too, PKCE required.
- What does it need to reach?
- A folder of its own: your application only ever sees one folder in each user’s Drive. Pick this unless you are building a file manager or a sync tool. See The application folder.
- The whole Drive: for file managers and sync tools.
- Tick I accept the Drime API terms.
- under Settings, add your redirect URLs (up to 10, see the rules);
- under Permissions, tick the scopes your application needs, and nothing more.
The secret key is shown once, when it is created. Drime keeps only a fingerprint of it. If you lose it, create a new one from Settings: the old one stops working immediately.
Next steps
Authorization flow
Send the user to Drime, get a code, exchange it for tokens
Scopes
What each permission opens, and what no application can have
The application folder
Working inside one folder of each user’s Drive
Webhooks
Get told when a connected account changes
Errors and limits
What each error means and what to do about it
Going to production
Lift the 25 users limit