Connect Dislab (OAuth) for partner apps

For apps used by many businesses: each owner connects their own Dislab with one click, no API keys to copy.

If your app serves many businesses, use “Connect Dislab” rather than asking each owner for an API key. It’s OAuth 2.0 with the authorization code flow and PKCE (S256), as Canva’s Publish to Dislab uses.

  1. Email support@dislab.app with your app’s name, its redirect addresses and what it needs to do. We register it and send you a client id and secret.
  2. Send the owner to the consent page:
    https://app.dislab.app/oauth/authorize
      ?response_type=code
      &client_id=CLIENT_ID
      &redirect_uri=https://yourapp.example/dislab/callback
      &scope=media:write
      &state=RANDOM
      &code_challenge=BASE64URL_SHA256_OF_VERIFIER
      &code_challenge_method=S256
    They sign in, see what your app may do, and press Allow (or Cancel, which sends error=access_denied).
  3. You get code and state back at your redirect address. The code works once, for 10 minutes. Swap it for tokens from your server:
    curl -X POST https://dqeiiqecdxqguwrilond.supabase.co/functions/v1/api/v1/oauth/token \
      -u CLIENT_ID:CLIENT_SECRET \
      -d grant_type=authorization_code \
      -d code=CODE \
      -d redirect_uri=https://yourapp.example/dislab/callback \
      -d code_verifier=VERIFIER
  4. The answer has access_token (dla_…, lasts an hour), refresh_token (dlr_…, lasts 180 days) and scope. Call Dislab with Authorization: Bearer dla_….
  5. When the access token runs out (401), post grant_type=refresh_token and refresh_token to the same address. You get a new pair; the old refresh token stops working, so store the new one.

Scopes and what they reach

  • media:write: add photos and videos to the owner’s Media. GET /app/me says which account you’re connected to; POST /media/import with {"files": [{"url", "mime", "name"}]} (1 to 10 PNG, JPEG or MP4 files at public https links) adds them, and Dislab fetches and converts each.
  • embed: show the console inside your app (see Embedding Dislab in your app).

OAuth errors use the standard shape ({"error", "error_description"}). POST /oauth/revoke with token ends a connection from your side. Owners see and disconnect apps under Connected apps in Settings; after that, your tokens are refused with 401, and their account and content stay as they are.

Still stuck?

Email support@dislab.app, or send us a message. If it’s about a screen, tell us its name. We answer within one business day.

Contact us