seinopsys / oauth2-deviantart
DeviantArt OAuth 2.0 Client Provider for The PHP League OAuth2-Client
v1.2.0
2026-09-29 15:29 UTC
Requires
- php: >=7.1
- league/oauth2-client: ^2.7
Requires (Dev)
- mockery/mockery: ^1.6
- phpunit/phpunit: ^11.0
- ramsey/uuid: ^4.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-29 15:30:52 UTC
README
DeviantArt OAuth 2.0 support for the PHP League’s OAuth 2.0 Client.
Installation
$ composer require seinopsys/oauth2-deviantart
Usage
You can get your OAuth client credentials here.
$provider = new SeinopSys\OAuth2\Client\Provider\DeviantArtProvider([ 'clientId' => 'client_id', 'clientSecret' => 'client_secret', 'redirectUri' => 'http://example.com/auth', ]); $accessToken = $provider->getAccessToken('authorization_code', [ 'code' => $_GET['code'], 'scope' => ['user','browse'] // optional, defaults to ['user'] ]); $actualToken = $accessToken->getToken(); $refreshToken = $accessToken->getRefreshToken(); // Once it expires $newAccessToken = $provider->getAccessToken('refresh_token', [ 'refresh_token' => $refreshToken ]);
PKCE
DeviantArt requires PKCE for newly registered applications; without it the
authorization page fails with "The code_challenge parameter is required." Enable it with the pkceMethod
option (requires league/oauth2-client 2.7+), and keep the generated code verifier until the callback:
$provider = new SeinopSys\OAuth2\Client\Provider\DeviantArtProvider([ 'clientId' => 'client_id', 'clientSecret' => 'client_secret', 'redirectUri' => 'http://example.com/auth', 'pkceMethod' => SeinopSys\OAuth2\Client\Provider\DeviantArtProvider::PKCE_METHOD_S256, ]); // Starting the flow $authUrl = $provider->getAuthorizationUrl(); $_SESSION['oauth2state'] = $provider->getState(); $_SESSION['oauth2pkceCode'] = $provider->getPkceCode(); header("Location: $authUrl"); // In the callback, after checking the state $provider->setPkceCode($_SESSION['oauth2pkceCode']); $accessToken = $provider->getAccessToken('authorization_code', [ 'code' => $_GET['code'], ]);
PKCE is off by default, so existing integrations that don't store the verifier keep working unchanged.