Skip to main content
Use OAuth when your application works on other people’s Drime accounts. The user signs in on Drime, sees what your application asks for and approves it. Your application receives a token limited to what they approved, and never sees their password.
For scripts and tools that only use your own account, a personal access token is simpler.

The standard

Drime implements OAuth 2.0 with the authorization code grant and PKCE (RFC 6749, RFC 7636, and RFC 8252 for native apps). A standard OAuth 2 client library works as is. These URLs carry no version number: only the data API is versioned (/api/v1). Point a generic client at the discovery URL and it configures itself. Drime does not implement OpenID Connect: there is no ID token and no userinfo endpoint. To know who authorized your application, call GET /users/me with their token.

Create an application

Open the developer console, click Create application and answer:
  1. Name: what your users see on the authorization screen. A name with the word “Drime” or “official” in it is refused, so that nobody can pass for Drime itself.
  2. What are you building?
    • A website or a server: a confidential client. You get a secret key, to keep on your server.
    • A desktop or mobile app: a public client. No secret key, and PKCE is required.
    • A script, just for me: a public client too, PKCE required.
  3. What does it need to reach?
    • A folder of its own: your application only ever sees one folder in each user’s Drive. Pick this unless you are building a file manager or a sync tool. See The application folder.
    • The whole Drive: for file managers and sync tools.
  4. Tick I accept the Drime API terms.
What your application can reach cannot change once someone has connected it. Widening it would give an application approved for one folder access to the whole Drive, behind a screen the user already saw. While nobody is connected you can still change it; after that, create a new application.
Your application exists right away, in Development, limited to 25 connected users. Build and test against it straight away, and send it for review when you want to lift the limit. Then, in your application:
  • under Settings, add your redirect URLs (up to 10, see the rules);
  • under Permissions, tick the scopes your application needs, and nothing more.
The secret key is shown once, when it is created. Drime keeps only a fingerprint of it. If you lose it, create a new one from Settings: the old one stops working immediately.

Next steps

Authorization flow

Send the user to Drime, get a code, exchange it for tokens

Scopes

What each permission opens, and what no application can have

The application folder

Working inside one folder of each user’s Drive

Webhooks

Get told when a connected account changes

Errors and limits

What each error means and what to do about it

Going to production

Lift the 25 users limit