Connect Dislab (OAuth) for partner apps
For apps used by many businesses: each owner connects their own Dislab with one click, no API keys to copy.
If your app serves many businesses, use “Connect Dislab” rather than asking each owner for an API key. It’s OAuth 2.0 with the authorization code flow and PKCE (S256), as Canva’s Publish to Dislab uses.
- Email support@dislab.app with your app’s name, its redirect addresses and what it needs to do. We register it and send you a client id and secret.
- Send the owner to the consent page:
They sign in, see what your app may do, and press Allow (or Cancel, which sendshttps://app.dislab.app/oauth/authorize ?response_type=code &client_id=CLIENT_ID &redirect_uri=https://yourapp.example/dislab/callback &scope=media:write &state=RANDOM &code_challenge=BASE64URL_SHA256_OF_VERIFIER &code_challenge_method=S256error=access_denied). - You get
codeandstateback at your redirect address. The code works once, for 10 minutes. Swap it for tokens from your server:curl -X POST https://dqeiiqecdxqguwrilond.supabase.co/functions/v1/api/v1/oauth/token \ -u CLIENT_ID:CLIENT_SECRET \ -d grant_type=authorization_code \ -d code=CODE \ -d redirect_uri=https://yourapp.example/dislab/callback \ -d code_verifier=VERIFIER - The answer has
access_token(dla_…, lasts an hour),refresh_token(dlr_…, lasts 180 days) andscope. Call Dislab withAuthorization: Bearer dla_…. - When the access token runs out (
401), postgrant_type=refresh_tokenandrefresh_tokento the same address. You get a new pair; the old refresh token stops working, so store the new one.
Scopes and what they reach
media:write: add photos and videos to the owner’s Media.GET /app/mesays which account you’re connected to;POST /media/importwith{"files": [{"url", "mime", "name"}]}(1 to 10 PNG, JPEG or MP4 files at public https links) adds them, and Dislab fetches and converts each.embed: show the console inside your app (see Embedding Dislab in your app).
OAuth errors use the standard shape ({"error", "error_description"}). POST /oauth/revoke with token ends a connection from your side. Owners see and disconnect apps under Connected apps in Settings; after that, your tokens are refused with 401, and their account and content stay as they are.
Thanks for telling us. If something’s missing, tell us what and we’ll add it.
Still stuck?
Email support@dislab.app, or send us a message. If it’s about a screen, tell us its name. We answer within one business day.