Skip to content
PuraPura Developers
Developers/Connect button

Connect button

Browser connection, per-tab state and protected callback.

Integrate the public button

createConnectButton builds the button and starts a PKCE flow with per-tab state. The browser returns to the callback in the same tab. A client secret must never be included in these options.

typescript
import {createConnectButton, completeBrowserConnection} from '@pura-ai/sdk';

const options = {
  apiBase: 'https://ai.puradigital.it/v1',
  clientId: 'YOUR_PUBLIC_CLIENT_ID',
  redirectUri: 'https://your-app.example/pura/callback',
};
document.querySelector('#pura-connect')!.append(
  createConnectButton({...options, locale: 'it', onError: showError})
);
// On the callback page, in the same tab:
const tokens = await completeBrowserConnection(options);
await userTokenStore.set(tokens);

Button in a confidential SaaS

Your UI button can open a backend endpoint that generates createAuthorization. Keep pending state in the backend session, exchange on the server and return to an app page. Do not use completeBrowserConnection to send a client secret from the browser.

Handling the return

Helpers verify state, callback and expiry before exchange. Show a clear error and a fresh button for denied or expired flows. Avoid analytics and logs that record the full URL containing the code.

Disconnect one app

The user can revoke a connection in the Pura console. Revocation invalidates that app’s tokens; other connected apps continue working. Also remove the local OAuth session when the user disconnects in your app.