Authorization

์น˜์ง€์ง Open API ์‚ฌ์šฉ๊ณผ ์ธ์ฆ์— ๊ด€๋ จ๋œ ๋ฌธ์„œ์ž…๋‹ˆ๋‹ค. ๊ฐ€์ด๋“œ์— ์ž‘์„ฑ๋œ API ๋ช…์„ธ์™€ ์ธ์ฆ ํ”Œ๋กœ์šฐ๋Š” ์ดํ›„ ๊ฐœ๋ฐœ ์ƒํ™ฉ์— ๋”ฐ๋ผ ๋ณ€๊ฒฝ ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


์ธ์ฆ ์ฝ”๋“œ ์š”์ฒญ ๋ฐ ๋ฐœ๊ธ‰

์น˜์ง€์ง Access Token ๋ฐœ๊ธ‰์„ ์œ„ํ•œ ์ธ์ฆ ์ฝ”๋“œ(Authorization Code)๋ฅผ ์š”์ฒญํ•ฉ๋‹ˆ๋‹ค. ์š”์ฒญ redirectUri ๋กœ Access Token ๋ฐœ๊ธ‰์„ ์œ„ํ•œ code ์™€ state ๊ฐ€ ์ „๋‹ฌ๋ฉ๋‹ˆ๋‹ค. ์ธ์ฆ ์ฝ”๋“œ๋ฅผ ์š”์ฒญํ•  ๋„๋ฉ”์ธ์€ ์•„๋ž˜์™€ ๊ฐ™์œผ๋ฉฐ, OPEN API์™€๋Š” ๋‹ค๋ฅธ ๋ณ„๋„์˜ ๋„๋ฉ”์ธ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

*์ฃผ์˜์‚ฌํ•ญ: ์š”์ฒญ redirectUri ๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋“ฑ๋ก์‹œ ์ž…๋ ฅํ•œ ๋กœ๊ทธ์ธ ๋ฆฌ๋””๋ ‰์…˜ URL ๊ณผ ์ผ์น˜ํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.

URL Path

GET https://chzzk.naver.com/account-interlock

Request Param

Key
Type
Required
Example

clientId

String

*

fefb6bbb-00c2-497c-afc2-XXXXXXXXXXXX

redirectUri

String

*

http://localhost:8080/api/path

state

String

*

zxclDasdfA25

Response Parameter

Key
Type
Example

code

String

ygKEQQk3p0DjUsBjJradJmXXXXXXXX

state

String

zxclDasdfA25

์น˜์ง€์ง Access Token ๋ฐœ๊ธ‰

Open API ์‚ฌ์šฉ ์ค‘, ์œ ์ € ์ธ์ฆ์„ ์œ„ํ•œ ํ† ํฐ์„ ๋ฐœ๊ธ‰ ๋ฐ›์Šต๋‹ˆ๋‹ค. Access Token ์˜ ๋งŒ๋ฃŒ๊ธฐ๊ฐ„์€ 1์ผ, Refresh Token ์˜ ๋งŒ๋ฃŒ๊ธฐ๊ฐ„์€ 30์ผ ์ž…๋‹ˆ๋‹ค.

URL Path

POST /auth/v1/token

Request Body

Key
Type
Example

grantType

String

authorization_code ๊ณ ์ •

clientId

String

fefb6bbb-00c2-497c-afc2-XXXXXXXXXXXX

clientSecret

String

VeIMuc9XGle7PSxIVYNwPpI2OEk_9gXoW_XXXXXXXXX

code

String

ygKEQQk3p0DjUsBjJradJmXXXXXXXX

state

String

zxclDasdfA25

Response Body

Key
Type
Example

accessToken

String

FFok65zQFQVcFvH2eJ7SS7SBFlTXt0EZ10L5XXXXXXXX

refreshToken

String

NWG05CKHAsz4k4d3PB0wQUV9ugGlp0YuibQ4XXXXXXXX

tokenType

String

Bearer ๊ณ ์ •

expiresIn

String

86400

์น˜์ง€์ง Access Token ๊ฐฑ์‹ 

Access Token์€ ๋งŒ๋ฃŒ ์ฃผ๊ธฐ๋ฅผ ๊ฐ–์Šต๋‹ˆ๋‹ค. ํ•ด๋‹น ๋งŒ๋ฃŒ ์ฃผ๊ธฐ๊ฐ€ ์ง€๋‚˜๋ฉด ํ•ด๋‹น Access Token์„ ์‚ฌ์šฉํ•œ API ํ˜ธ์ถœ์€ 401(INVALID_TOKEN) ์‘๋‹ต์„ ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค. Access Token์ด ๋งŒ๋ฃŒ๋˜๋ฉด, Refresh Token์„ ํ†ตํ•˜์—ฌ Access Token์„ ์žฌ๋ฐœ๊ธ‰ ๋ฐ›์•„ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

Refresh Token์€ Access Token ๋ณด๋‹ค ๊ธด ๋งŒ๋ฃŒ๊ธฐ๊ฐ„์„ ๊ฐ€์ง€๋ฉฐ, ์ผํšŒ์šฉ์œผ๋กœ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. Refresh Token ๋˜ํ•œ ๋งŒ๋ฃŒ๋˜๋ฉด Access Token ๋ฐœ๊ธ‰ ๊ณผ์ •์„ ํ†ตํ•ด ์ƒˆ๋กœ์šด Access Token์„ ๋ฐœ๊ธ‰๋ฐ›์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค.

URL Path

POST /auth/v1/token

Request Body

Key
Type
Example

grantType

String

refresh_token ๊ณ ์ •

refreshToken

String

NWG05CKHAsz4k4d3PB0wQUV9ugGlp0YuibQ4XXXXXXXX

clientId

String

fefb6bbb-00c2-497c-afc2-XXXXXXXXXXXX

clientSecret

String

VeIMuc9XGle7PSxIVYNwPpI2OEk_9gXoW_XXXXXXXXX

Response Body

Key
Type
Example

accessToken

String

motTJ-NZ-fev3cmaTMydzYk_zyw524C9ZYdNXXXXXXXX

refreshToken

String

EDpM_1RxiOwhbNBpNUbiuEZOrb7Dbd6Y7rivXXXXXXXX

tokenType

String

Bearer ๊ณ ์ •

expiresIn

String

86400

scope

String

์ฑ„๋„ ์กฐํšŒ

์น˜์ง€์ง Access Token ์‚ญ์ œ

์œ ์ €๊ฐ€ ๋กœ๊ทธ์•„์›ƒํ•˜๋Š” ๋“ฑ, ํ•ด๋‹น Access Token, Refresh Token ์˜ revoke ๊ฐ€ ํ•„์š”ํ•  ๊ฒฝ์šฐ ํ˜ธ์ถœํ•ฉ๋‹ˆ๋‹ค. ์š”์ฒญํ•œ Token ๊ณผ ๋™์ผํ•œ ์ธ์ฆ ๊ณผ์ •์„ ๊ฑฐ์นœ ๋ชจ๋“  Token ์ด ์ œ๊ฑฐ๋ฉ๋‹ˆ๋‹ค. (clientId ์™€ user ๊ฐ€ ๋™์ผํ•œ Token)

URL Path

POST /auth/v1/token/revoke

Request Body

Key
Type
Example

clientId

String

fefb6bbb-00c2-497c-afc2-XXXXXXXXXXXX

clientSecret

String

VeIMuc9XGle7PSxIVYNwPpI2OEk_9gXoW_XXXXXXXXX

token

String

motTJ-NZ-fev3cmaTMydzYk_zyw524C9ZYdNXXXXXXXX

tokenTypeHint

String

  • access_token (default)

  • refresh_token

Last updated