marsaldev / oauth2-amazon
Amazon OAuth 2.0 support for the PHP League's OAuth 2.0 Client
Requires
- php: ^8.2
- league/oauth2-client: ^2.7
Requires (Dev)
- mockery/mockery: ^1.6
- phpunit/phpunit: ^11.5
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-09 08:19:29 UTC
README
This package provides Amazon OAuth 2.0 support for the PHP League's OAuth 2.0 Client.
Installation
composer require marsaldev/oauth2-amazon
Amazon Setup
Before you can use this provider, you need to register your application with Amazon to get a Client ID and Client Secret:
- Sign in to the Amazon Developer Console.
- Go to Apps & Services → Login with Amazon and click Create a New Security Profile.
- Fill in the Security Profile Name, Security Profile Description, and Consent Privacy Notice URL, then save.
- Open the security profile you just created and go to the Web Settings tab: this is where you'll find your Client ID and Client Secret.
- Still under Web Settings, click Edit and set:
- Allowed Origins — the origin(s) your application is served from (e.g.
https://example.com) - Allowed Return URLs — the exact redirect URI your app uses to receive the authorization
code; this must match the
redirectUripassed to the provider below
- Allowed Origins — the origin(s) your application is served from (e.g.
- Use the Client ID, Client Secret, and redirect URI in your application as shown in Usage below.
Note: the profile scope is granted by default. The postal_code scope and the payments:*
scopes used in the example below are tied to Amazon Pay and may require your security profile to be
separately approved for those APIs before Amazon will grant them.
Usage
$amazonProvider = new \MichaelKaefer\OAuth2\Client\Provider\Amazon([ 'clientId' => 'yourId', // The client ID assigned to you by Amazon 'clientSecret' => 'yourSecret', // The client password assigned to you by Amazon 'redirectUri' => 'yourRedirectUri' // The return URL you specified for your app on Amazon ]); // Get authorization code if (!isset($_GET['code'])) { // Options are optional, defaults to 'profile' only $options = ['scope' => 'profile postal_code payments:widget payments:shipping_address payments:billing_address']; // Get authorization URL $authorizationUrl = $amazonProvider->getAuthorizationUrl($options); // Get state and store it to the session $_SESSION['oauth2state'] = $amazonProvider->getState(); // Redirect user to authorization URL header('Location: ' . $authorizationUrl); exit; // Check for errors } elseif (empty($_GET['state']) || (isset($_SESSION['oauth2state']) && $_GET['state'] !== $_SESSION['oauth2state'])) { if (isset($_SESSION['oauth2state'])) { unset($_SESSION['oauth2state']); } exit('Invalid state'); } else { // Get access token try { $accessToken = $amazonProvider->getAccessToken( 'authorization_code', [ 'code' => $_GET['code'] ] ); } catch (\League\OAuth2\Client\Provider\Exception\IdentityProviderException $e) { exit($e->getMessage()); } // Get resource owner try { $resourceOwner = $amazonProvider->getResourceOwner($accessToken); } catch (\League\OAuth2\Client\Provider\Exception\IdentityProviderException $e) { exit($e->getMessage()); } // Now you can store the results to session etc. $_SESSION['accessToken'] = $accessToken; $_SESSION['resourceOwner'] = $resourceOwner; var_dump( $resourceOwner->getId(), $resourceOwner->getName(), $resourceOwner->getPostalCode(), $resourceOwner->getEmail(), $resourceOwner->toArray() ); }
For more information see the PHP League's general usage examples.
Testing
$ ./vendor/bin/phpunit
License
The MIT License (MIT). Please see License File for more information.