> ## Documentation Index
> Fetch the complete documentation index at: https://docs.drime.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth Overview

> Let other Drime users connect your application to their account

Use OAuth when your application works on **other people's** Drime accounts. The user signs in on Drime, sees what your application asks for and approves it. Your application receives a token limited to what they approved, and never sees their password.

<Tip>
  For scripts and tools that only use your own account, a [personal access token](/authentication#personal-access-tokens) is simpler.
</Tip>

## The standard

Drime implements OAuth 2.0 with the authorization code grant and PKCE (RFC 6749, RFC 7636, and RFC 8252 for native apps). A standard OAuth 2 client library works as is.

| Endpoint | URL |
| - | - |
| Discovery (RFC 8414) | `GET https://app.drime.cloud/.well-known/oauth-authorization-server` |
| Authorization | `GET https://app.drime.cloud/oauth/authorize` |
| Token | `POST https://app.drime.cloud/oauth/token` |
| Revocation (RFC 7009) | `POST https://app.drime.cloud/oauth/revoke` |
| API | `https://app.drime.cloud/api/v1/...` |

These URLs carry no version number: only the data API is versioned (`/api/v1`). Point a generic client at the discovery URL and it configures itself.

Drime does not implement OpenID Connect: there is no ID token and no userinfo endpoint. To know who authorized your application, call [`GET /users/me`](/api-reference/user/get-logged-user) with their token.

## Create an application

Open the [developer console](https://app.drime.cloud/developers), click **Create application** and answer:

1. **Name**: what your users see on the authorization screen. A name with the word "Drime" or "official" in it is refused, so that nobody can pass for Drime itself.
2. **What are you building?**
   * **A website or a server**: a confidential client. You get a secret key, to keep on your server.
   * **A desktop or mobile app**: a public client. No secret key, and PKCE is required.
   * **A script, just for me**: a public client too, PKCE required.
3. **What does it need to reach?**
   * **A folder of its own**: your application only ever sees one folder in each user's Drive. Pick this unless you are building a file manager or a sync tool. See [The application folder](/oauth/app-folder).
   * **The whole Drive**: for file managers and sync tools.
4. Tick **I accept the Drime API terms**.

<Warning>
  What your application can reach cannot change once someone has connected it. Widening it would give an application approved for one folder access to the whole Drive, behind a screen the user already saw. While nobody is connected you can still change it; after that, create a new application.
</Warning>

Your application exists right away, in **Development**, limited to **25 connected users**. Build and test against it straight away, and [send it for review](/oauth/going-to-production) when you want to lift the limit.

Then, in your application:

* under **Settings**, add your redirect URLs (up to 10, see the [rules](/oauth/authorization-flow#redirect-urls));
* under **Permissions**, tick the scopes your application needs, and nothing more.

<Note>
  The secret key is shown once, when it is created. Drime keeps only a fingerprint of it. If you lose it, create a new one from **Settings**: the old one stops working immediately.
</Note>

## Next steps

<CardGroup cols={2}>
  <Card title="Authorization flow" icon="key" href="/oauth/authorization-flow">
    Send the user to Drime, get a code, exchange it for tokens
  </Card>

  <Card title="Scopes" icon="list-check" href="/oauth/scopes">
    What each permission opens, and what no application can have
  </Card>

  <Card title="The application folder" icon="folder" href="/oauth/app-folder">
    Working inside one folder of each user's Drive
  </Card>

  <Card title="Webhooks" icon="bell" href="/oauth/webhooks">
    Get told when a connected account changes
  </Card>

  <Card title="Errors and limits" icon="triangle-exclamation" href="/oauth/errors-and-limits">
    What each error means and what to do about it
  </Card>

  <Card title="Going to production" icon="rocket" href="/oauth/going-to-production">
    Lift the 25 users limit
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.