User sign-in: OAuth 2.1 + OIDC
Register a public client for this app. ARK uses Authorization Code + S256 PKCE and exact redirect URI matching. The public client ID identifies the app; it is not a secret. No API key or client secret is required for end-user sign-in.
Register a public appDiscovery
https://accounts.arkflame.com/api/auth/.well-known/openid-configuration
Treat the discovery document as authoritative for authorization, token, UserInfo, JWKS, revocation, introspection and logout endpoints.
Authorize with PKCE
Generate state and a one-use verifier with a cryptographic random generator. Keep both in a short-lived HttpOnly app cookie, then send the challenge to the authorization endpoint. Ask for offline access only if the app needs a long-running session.
GET https://accounts.arkflame.com/api/auth/oauth2/authorize ?client_id=YOUR_PUBLIC_CLIENT_ID &redirect_uri=https%3A%2F%2Fapp.arkflame.com%2Fauth%2Fcallback &response_type=code &scope=openid%20profile%20email &code_challenge=BASE64URL_SHA256_VERIFIER &code_challenge_method=S256 &state=ONE_TIME_RANDOM_VALUE
Exchange the code
POST https://accounts.arkflame.com/api/auth/oauth2/token Content-Type: application/x-www-form-urlencoded grant_type=authorization_code&code=...&redirect_uri=...&client_id=...&code_verifier=...
Exchange the code on your app server. Keep the access token server-side, fetch UserInfo from the discovered endpoint, then discard the provider token after creating your app session.
Resolve an ARK user/session
Preferred standard endpoint:
GET https://accounts.arkflame.com/api/auth/oauth2/userinfo Authorization: Bearer ARK_ACCESS_TOKEN
Stable ARK convenience alias for server-side integrations:
GET https://accounts.arkflame.com/api/v1/session Authorization: Bearer ARK_ACCESS_TOKEN
Server-to-server: ARK API keys
Generate keys under Developer Console → API keys. Keys are hashed at rest, shown in full only once, prefixed ark_live_, permissioned and individually rate-limited. They authenticate developer API calls only; they never impersonate an end-user session.
GET https://accounts.arkflame.com/api/v1/developer/me x-api-key: ark_live_...
Public service metadata
GET https://accounts.arkflame.com/api/v1/metadata GET https://accounts.arkflame.com/api/v1/health
No API key is required for metadata or health.
Claims contract
{
"sub": "immutable ARK user id",
"email": "[email protected]",
"email_verified": true,
"name": "Display name",
"picture": "https://accounts.arkflame.com/avatar.png"
}Use sub as your application's foreign identity key. Never key users by email.