{
  "openapi" : "3.1.0",
  "info" : {
    "title" : "Frontend Authentication",
    "version" : "1.0.0",
    "description" : "Provides OAuth JWT endpoints for app login, token refresh and logout."
  },
  "paths" : {
    "/oauth/login" : {
      "post" : {
        "operationId" : "post-oauth-login",
        "summary" : "Request or refresh OAuth JWT tokens",
        "description" : "Issues JWT access and refresh tokens for frontend/mobile app clients.\nSupports grant_type=password for username/password login and grant_type=refresh_token for refreshing an\nexisting session without cookies.\n",
        "requestBody" : {
          "required" : true,
          "content" : {
            "application/x-www-form-urlencoded" : {
              "examples" : {
                "Password grant" : {
                  "value" : "grant_type=password&client_id=flutter-app&username=user@example.com&password=secret"
                },
                "Refresh grant" : {
                  "value" : "grant_type=refresh_token&client_id=flutter-app&refresh_token=<refresh-token>"
                }
              }
            }
          }
        },
        "responses" : {
          "200" : {
            "description" : "",
            "content" : {
              "application/json" : {
                "examples" : {
                  "example1" : {
                    "value" : {
                      "access_token" : "<jwt-access-token>",
                      "token_type" : "Bearer",
                      "expires_in" : 900,
                      "refresh_token" : "<jwt-refresh-token>"
                    }
                  }
                }
              }
            }
          },
          "400" : {
            "description" : "The grant request is invalid.",
            "content" : {
              "application/json" : {
                "examples" : {
                  "example1" : {
                    "value" : {
                      "error" : "invalid_grant",
                      "error_description" : "Invalid refresh_token request"
                    }
                  }
                }
              }
            }
          }
        }
      }
    },
    "/oauth/logout" : {
      "post" : {
        "operationId" : "post-oauth-logout",
        "summary" : "Logout and revoke OAuth JWT tokens",
        "description" : "Revokes the bearer access token used for the request. If a matching refresh_token is supplied in the form\nbody, it is revoked as well. The endpoint does not use cookies.\n",
        "parameters" : [ {
          "name" : "Authorization",
          "in" : "header",
          "required" : true,
          "description" : "Bearer access token to revoke.",
          "schema" : {
            "type" : "string"
          }
        } ],
        "requestBody" : {
          "required" : false,
          "content" : {
            "application/x-www-form-urlencoded" : {
              "examples" : {
                "example1" : {
                  "value" : "refresh_token=<refresh-token>"
                }
              }
            }
          }
        },
        "responses" : {
          "200" : {
            "description" : "",
            "content" : {
              "application/json" : {
                "examples" : {
                  "example1" : {
                    "value" : {
                      "success" : true
                    }
                  }
                }
              }
            }
          },
          "401" : {
            "description" : "The bearer token is missing, invalid or already revoked.",
            "content" : {
              "application/json" : {
                "examples" : {
                  "example1" : {
                    "value" : {
                      "error" : "invalid_token",
                      "error_description" : "Missing, invalid or revoked bearer token"
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  }
}