Search by

seinopsys / oauth2-deviantart

SeinopSys

DeviantArt OAuth 2.0 Client Provider for The PHP League OAuth2-Client

Package info

github.com/SeinopSys/oauth2-deviantart

pkg:composer/seinopsys/oauth2-deviantart

Statistics

Installs: 2 501

Dependents: 1

Suggesters: 0

Stars: 0

Open Issues: 0

v1.2.0 2026-09-29 15:29 UTC

This package is auto-updated.

Last update: 2026-09-29 15:30:52 UTC


README

Build Status Latest Stable Version

DeviantArt OAuth 2.0 support for the PHP League’s OAuth 2.0 Client.

Installation

$ composer require seinopsys/oauth2-deviantart

Usage

You can get your OAuth client credentials here.

$provider = new SeinopSys\OAuth2\Client\Provider\DeviantArtProvider([
	'clientId' => 'client_id',
	'clientSecret' => 'client_secret',
	'redirectUri' => 'http://example.com/auth',
]);

$accessToken = $provider->getAccessToken('authorization_code', [
	'code' => $_GET['code'],
	'scope' => ['user','browse'] // optional, defaults to ['user']
]);
$actualToken = $accessToken->getToken();
$refreshToken = $accessToken->getRefreshToken();

// Once it expires

$newAccessToken = $provider->getAccessToken('refresh_token', [
	'refresh_token' => $refreshToken
]);

PKCE

DeviantArt requires PKCE for newly registered applications; without it the authorization page fails with "The code_challenge parameter is required." Enable it with the pkceMethod option (requires league/oauth2-client 2.7+), and keep the generated code verifier until the callback:

$provider = new SeinopSys\OAuth2\Client\Provider\DeviantArtProvider([
	'clientId' => 'client_id',
	'clientSecret' => 'client_secret',
	'redirectUri' => 'http://example.com/auth',
	'pkceMethod' => SeinopSys\OAuth2\Client\Provider\DeviantArtProvider::PKCE_METHOD_S256,
]);

// Starting the flow
$authUrl = $provider->getAuthorizationUrl();
$_SESSION['oauth2state'] = $provider->getState();
$_SESSION['oauth2pkceCode'] = $provider->getPkceCode();
header("Location: $authUrl");

// In the callback, after checking the state
$provider->setPkceCode($_SESSION['oauth2pkceCode']);
$accessToken = $provider->getAccessToken('authorization_code', [
	'code' => $_GET['code'],
]);

PKCE is off by default, so existing integrations that don't store the verifier keep working unchanged.