ARK Accounts

ARK Accounts for developers

One identity layer for your app.

Add a “Login with ARK” popup for end-user sign-in. People choose email/password, Google, or Discord on ARK Accounts; your app receives only the verified identity. Sign-in uses a public OAuth client with PKCE, no API key, and no client secret.

User sign-in: OAuth 2.1 + OIDC

Register a public client for this app. ARK uses Authorization Code + S256 PKCE and exact redirect URI matching. The public client ID identifies the app; it is not a secret. No API key or client secret is required for end-user sign-in.

Register a public app

Discovery

https://accounts.arkflame.com/api/auth/.well-known/openid-configuration

Treat the discovery document as authoritative for authorization, token, UserInfo, JWKS, revocation, introspection and logout endpoints.

Authorize with PKCE

Generate state and a one-use verifier with a cryptographic random generator. Keep both in a short-lived HttpOnly app cookie, then send the challenge to the authorization endpoint. Ask for offline access only if the app needs a long-running session.

GET https://accounts.arkflame.com/api/auth/oauth2/authorize
  ?client_id=YOUR_PUBLIC_CLIENT_ID
  &redirect_uri=https%3A%2F%2Fapp.arkflame.com%2Fauth%2Fcallback
  &response_type=code
  &scope=openid%20profile%20email
  &code_challenge=BASE64URL_SHA256_VERIFIER
  &code_challenge_method=S256
  &state=ONE_TIME_RANDOM_VALUE

Exchange the code

POST https://accounts.arkflame.com/api/auth/oauth2/token
Content-Type: application/x-www-form-urlencoded

grant_type=authorization_code&code=...&redirect_uri=...&client_id=...&code_verifier=...

Exchange the code on your app server. Keep the access token server-side, fetch UserInfo from the discovered endpoint, then discard the provider token after creating your app session.

Resolve an ARK user/session

Preferred standard endpoint:

GET https://accounts.arkflame.com/api/auth/oauth2/userinfo
Authorization: Bearer ARK_ACCESS_TOKEN

Stable ARK convenience alias for server-side integrations:

GET https://accounts.arkflame.com/api/v1/session
Authorization: Bearer ARK_ACCESS_TOKEN

Server-to-server: ARK API keys

Generate keys under Developer Console → API keys. Keys are hashed at rest, shown in full only once, prefixed ark_live_, permissioned and individually rate-limited. They authenticate developer API calls only; they never impersonate an end-user session.

GET https://accounts.arkflame.com/api/v1/developer/me
x-api-key: ark_live_...

Public service metadata

GET https://accounts.arkflame.com/api/v1/metadata
GET https://accounts.arkflame.com/api/v1/health

No API key is required for metadata or health.

Claims contract

{
  "sub": "immutable ARK user id",
  "email": "[email protected]",
  "email_verified": true,
  "name": "Display name",
  "picture": "https://accounts.arkflame.com/avatar.png"
}

Use sub as your application's foreign identity key. Never key users by email.