AgeOnce Docs
API Reference

OAuth Flow

OAuth 2.0 Authorization Code Flow for age verification

OAuth 2.0 Flow

AgeOnce uses the standard OAuth 2.0 Authorization Code Flow for age verification.

Step 1: Redirect to verification

Endpoint

Open the verification app and pass the query string on the site root. There is no /verify path.

GET https://app.ageonce.com/?client_id=...&redirect_uri=...&state=...&age_required=18

Parameters

ParameterTypeRequiredDescription
client_idstringYesYour Client ID
redirect_uristringYesURL for user redirect after verification
statestringRecommendedRandom string for CSRF protection
age_requiredstringOptionalMinimum age to verify (e.g. 18, 21). Default: 18

Example URL

https://app.ageonce.com/?client_id=ap_live_your_client_id&redirect_uri=https%3A%2F%2Fexample.com%2Fcallback&state=xyz789&age_required=18

Important

redirect_uri must be pre-registered in your AgeOnce Dashboard.

Step 2: User completes verification

On the AgeOnce page:

  1. User grants camera permission
  2. Completes biometric verification
  3. System determines age compliance

Step 3: Redirect back with code

After successful verification, the user is redirected to your redirect_uri:

https://example.com/callback?code=auth_code_123&state=xyz789

Callback parameters

ParameterDescription
codeAuthorization code to exchange for token
stateSame state you sent

Errors

A failed or cancelled check stays on the AgeOnce page. The browser is redirected to redirect_uri only after a successful check, with code and state.

Step 4: Exchange code for token

Your backend exchanges code for access_token:

POST https://api.ageonce.com/api/oauth/token

Learn more about Token Exchange →

State parameter

State is used for CSRF attack protection:

// Generate state
const state = crypto.randomBytes(16).toString('hex');

// Store in session
session.oauthState = state;

// On callback - verify
if (req.query.state !== session.oauthState) {
  throw new Error('Invalid state');
}

Always verify state! Without this, your app is vulnerable to CSRF attacks.

Flow diagram

┌──────────┐                              ┌──────────┐
│  Client  │                              │ AgeOnce  │
└────┬─────┘                              └────┬─────┘
     │                                         │
     │  1. GET /?client_id=...                │
     │────────────────────────────────────────►│
     │                                         │
     │         2. User verifies age            │
     │                                         │
     │  3. Redirect: callback?code=...        │
     │◄────────────────────────────────────────│
     │                                         │
     │  4. POST api.ageonce.com/api/oauth/token   │
     │────────────────────────────────────────►│
     │                                         │
     │  5. { access_token: "..." }            │
     │◄────────────────────────────────────────│
     │                                         │

Lifetime

ElementLifetime
Authorization code1 minute
Access token (access_token)10 minutes (expires_in: 600)

On this page