Search by

kangaroorewards / oauth2-kangaroo-rewards

KangarooRewards

Kangaroo Rewards OAuth 2.0 Client Provider for The PHP League OAuth2-Client

Package info

github.com/kangaroorewards/oauth2-kangaroo-rewards

pkg:composer/kangaroorewards/oauth2-kangaroo-rewards

Statistics

Installs: 204

Dependents: 0

Suggesters: 0

Stars: 1

Open Issues: 0

v3.0.0 2026-08-21 20:38 UTC

This package is auto-updated.

Last update: 2026-08-21 21:18:33 UTC


README

CI Latest Version Software License

This package provides Kangaroo Rewards OAuth 2.0 support for the PHP League's OAuth 2.0 Client.

This package is compliant with PSR-1, PSR-12, PSR-4, and PSR-7. If you notice compliance oversights, please send a patch via pull request.

Requirements

The following versions of PHP are supported.

  • PHP 8.1
  • PHP 8.2
  • PHP 8.3
  • PHP 8.4
  • PHP 8.5

Requires the curl and json extensions, and league/oauth2-client ^2.8.

Running PHP 7.x or older? Stay on the 2.x releases.

Installation

composer require kangaroorewards/oauth2-kangaroo-rewards:^3.0

Usage

Authorization Code Flow

session_start();

$provider = new KangarooRewards\OAuth2\Client\Provider\Kangaroo([
    'clientId' => CLIENT_ID,
    'clientSecret' => CLIENT_SECRET,
    'redirectUri' => REDIRECT_URI,
]);

if (!isset($_GET['code'])) {

    // If we don't have an authorization code then get one
    $authUrl = $provider->getAuthorizationUrl([]);
    $_SESSION['oauth2state'] = $provider->getState();
    
    echo '<a href="'.$authUrl.'">Log in with Kangaroo Rewards!</a>';
    exit;

// Check given state against previously stored one to mitigate CSRF attack
} elseif (empty($_GET['state']) || ($_GET['state'] !== $_SESSION['oauth2state'])) {

    unset($_SESSION['oauth2state']);
    echo 'Invalid state.';
    exit;

}

// Try to get an access token (using the authorization code grant)
$token = $provider->getAccessToken('authorization_code', [
    'code' => $_GET['code']
]);

try {

    // We got an access token, let's make some requests
    $resourceOwner = $provider->getResourceOwner($token);
    
    $http = new GuzzleHttp\Client;
    $response = $http->get('https://api.kangaroorewards.com/customers', [
        'headers' => [
            'User-Agent' => '{Client Name}',
            'Content-Type' => 'application/json',
            'Accept' => 'application/vnd.kangaroorewards.api.v1+json;',
            'Authorization' => 'Bearer ' . $token->getToken(),
        ]
    ]);
    $r = json_decode((string) $response->getBody(), true);

    echo '<pre>';
    var_export($resourceOwner->toArray());
    var_export($r);
    echo '</pre>';

} catch (Exception $e) {
    exit($e->getMessage());
}

echo '<pre>';
// Use this to interact with the API on the client behalf
var_dump($token->getToken());

echo '</pre>';

Grants

On top of the grants shipped with league/oauth2-client (authorization_code, refresh_token, client_credentials, password), this package registers two Kangaroo-specific grants:

// Requires: username, password
$token = $provider->getAccessToken('facebook', [
    'username' => $email,
    'password' => $facebookToken,
]);

// Requires: username, google_token
$token = $provider->getAccessToken('google', [
    'username' => $email,
    'google_token' => $googleToken,
]);

Resource owner

$owner = $provider->getResourceOwner($token);

$owner->getId();
$owner->getName();
$owner->getEmail();
$owner->getBusinessId();
$owner->getBusinessName();
$owner->toArray();

Every accessor returns null when the field is absent from the API response.

getBusinessId() and getBusinessName() read the business from the resource owner response, and /me only returns it when asked. Point urlResourceOwnerDetails at the include to populate them:

$provider = new KangarooRewards\OAuth2\Client\Provider\Kangaroo([
    'clientId' => CLIENT_ID,
    'clientSecret' => CLIENT_SECRET,
    'redirectUri' => REDIRECT_URI,
    'urlResourceOwnerDetails' => 'https://api.kangaroorewards.com/me?include=business',
]);

Testing

composer install
composer test
composer lint
composer check

Auto-fix style issues with:

./vendor/bin/phpcbf src tests --standard=psr12 -p

Contributing

Please see CONTRIBUTING for details.

Credits

License

The MIT License (MIT). Please see License File for more information.