OAuth & Sign in with Sporty
Sporty is an OAuth 2.1 and OpenID Connect provider. Your application can ask a member for permission, receive a scoped access token, and use it to read the things they agreed to — without ever seeing their password, and with the member able to take that access back at any time.
Everything here is standard. Any OAuth or OIDC client library will work; you should not need to write anything Sporty-specific.
Which flow you want
| You are building | Use |
|---|---|
| A web, mobile or desktop app that acts for the person using it | Authorization code + PKCE |
| "Sign in with Sporty" — you just need to know who someone is | Authorization code + PKCE, with the openid scope |
| A server-to-server integration acting for a club, with no person present | Client credentials |
| A booking system keeping its diary in step with a club's | Client credentials, see Syncing bookings |
| An AI agent or MCP client | Authorization code + PKCE, usually with dynamic registration |
There is no password grant and no implicit grant. OAuth 2.1 removes both.
Endpoints
Everything lives on https://api.sporty.plus.
| Purpose | Endpoint |
|---|---|
| Authorization | GET /oauth2/authorize |
| Token | POST /oauth2/token |
| Revocation (RFC 7009) | POST /oauth2/token/revoke |
| Dynamic registration (RFC 7591) | POST /oauth2/register |
| UserInfo | GET /oauth2/userinfo |
| JWKS | GET /oauth2/jwks |
Rather than hard-coding those, fetch one of the discovery documents:
curl https://api.sporty.plus/.well-known/openid-configuration
curl https://api.sporty.plus/.well-known/oauth-authorization-server
curl https://api.sporty.plus/.well-known/oauth-protected-resource
Where tokens work
An access token is spent on the partner API, https://api.sporty.plus/api/partner/v1.
It will not work anywhere else. In particular /api/v3, the API our own apps use, refuses
OAuth tokens outright and answers 403 with a message saying so. That surface is authorised
for people using our own interface, not for applications acting on their behalf, and letting
a token in there would grant far more than any consent screen described.