Reference

Endpoints

EndpointURL
Discoveryhttps://auth.motaware.com/.well-known/openid-configuration
Authorizationhttps://auth.motaware.com/connect/authorize
Tokenhttps://auth.motaware.com/connect/token
Userinfohttps://auth.motaware.com/connect/userinfo
Revocation (RFC 7009)https://auth.motaware.com/connect/revoke
End session (sign-out)https://auth.motaware.com/connect/logout
Signing keys (JWKS)https://auth.motaware.com/.well-known/jwks

The issuer (iss) is https://auth.motaware.com/, with a trailing slash. Supported flow: authorization code with PKCE (S256), required for every client type.

Scopes and claims

ScopeClaims (ID token and userinfo)
openidsub (required in every request)
emailemail, email_verified
profilename, given_name, family_name (when set), picture (when set)
offline_accessNo claims; the token response includes a refresh token

Access tokens carry sub, scope and client_id but no personal details. Read those from the ID token or userinfo.

The user id (sub)

  • It is pairwise per project: the same for a person across every client in your project, and different in anyone else's project.
  • It is never the person's Motaware account id, and you can't derive one from the other.
  • Treat it as an opaque string of at most 64 characters. Use it, not the email address, as the key for your user records.

Tokens

TokenLifetimeNotes
Access token15 minutesJWT signed with RS256; validate it against the JWKS. Send it as Authorization: Bearer.
ID tokenShortProves who signed in. Validate iss, aud, exp and nonce.
Refresh token30 daysOnly with offline_access. Refresh tokens may be rotated: always store the newest one.

Consent

  • The first time someone signs in to your app, Motaware shows a consent page with your app's name and the access it asks for. The person is asked again only when you ask for scopes they haven't granted.
  • prompt=consent always shows the consent page.
  • prompt=none never shows a page. If the person hasn't granted access yet, it returns error=consent_required; if they aren't signed in, login_required.
  • People can remove your app's access at any time under Connected apps in their Motaware Account. This revokes your refresh tokens at once, and the current access token expires within 15 minutes.

Sign-out

Send the person to the end-session endpoint with the ID token you received and a sign-out return URL registered on your client:

GET https://auth.motaware.com/connect/logout
    ?id_token_hint=eyJhbGciOiJSUzI1NiIs…
    &post_logout_redirect_uri=https%3A%2F%2Fapp.example.com%2F
    &state=xyz

This ends the person's Motaware session in that browser, for every app. People signing out of an outside app may be asked to confirm on a Motaware page.

Revoking tokens

When someone disconnects Motaware in your app, revoke the refresh token (RFC 7009):

POST https://auth.motaware.com/connect/revoke
Content-Type: application/x-www-form-urlencoded

token=…&token_type_hint=refresh_token&client_id=mw_yourclientid

Errors

ErrorWhen
access_deniedThe person pressed Cancel on the consent page.
consent_requiredprompt=none was sent, and the person hasn't granted access yet.
invalid_grantAt the token endpoint: the code or refresh token is expired or used, the person removed your app's access, or the client is turned off or its project suspended.
invalid_scopeYou asked for a scope your client isn't allowed to use, or one it isn't approved for in app review (authorization endpoint).
invalid_requestMissing PKCE, a redirect URL that isn't registered exactly, or another malformed request.

A client that is turned off or suspended shows people a Motaware page saying the app isn't available, instead of redirecting back to you.

Limits for unverified apps

  • Until Motaware has reviewed your app, at most 100 people besides you can authorize it. People who already authorized it keep working.
  • The consent page tells people the app is unverified.
  • Your logo is shown only after verification; until then the page shows your app name's first letter.
  • App and project names can't contain "Motaware".

To lift these limits and use API permissions, send your app for review.

Rate limits

The platform is free. Fair-use rate limits apply. Back off and retry when you get 429 Too Many Requests.