Connect with Pura
Register your application
Open Integrations in the Pura console. Register an exact HTTPS callback URL. Choose a public client for browser-only apps or a confidential client for a backend. A confidential secret is shown once and belongs only on your server.
Authorization and return
The SDK creates random state and a PKCE verifier, then redirects to GET /v1/integrations/oauth/authorize. Pura asks for explicit consent for inference and usage:read. On the registered callback, validate state and exchange the code with POST /v1/integrations/oauth/token. Browser Connect must return in the same tab. Pending flows expire after ten minutes. The token response includes pura_user_id. Store this verified account ID alongside tokens and the local connected user, and use it to match lifecycle events. Refresh must preserve that identity.
Refresh and disconnect
Access tokens last 15 minutes; refresh tokens last 30 days and rotate on use. Persist every replacement and serialize refresh across workers. Reuse revokes the token family. Users can disconnect one app on the Subscription page without revoking other apps or changing the account key. App owners can suspend an app, which permanently revokes its grants, tokens and pending codes. Reactivation requires fresh user consent. Rotate client secret shows a new confidential secret once and immediately rejects the old one; it does not revoke existing user grants.
import {createConnectButton, completeBrowserConnection} from '@pura-ai/sdk';
const options = {
apiBase: 'https://ai.puradigital.it/v1',
clientId: 'YOUR_REGISTERED_CLIENT_ID',
redirectUri: 'https://YOUR-APP/pura/callback',
};
document.querySelector('#pura-connect')!.append(
createConnectButton({...options, locale: 'it', onError: console.error})
);
// On the callback page, in the same tab:
const tokens = await completeBrowserConnection(options);
await userTokenStore.set(tokens);