OAuth & Sign in with Sporty

OAuth & Sign in with Sporty

Let people connect your application to their Sporty account, with their permission and nothing more.

Sporty is an OAuth 2.1 and OpenID Connect provider. Your application can ask a member for permission, receive a scoped access token, and use it to read the things they agreed to — without ever seeing their password, and with the member able to take that access back at any time.

Everything here is standard. Any OAuth or OIDC client library will work; you should not need to write anything Sporty-specific.

Which flow you want

You are buildingUse
A web, mobile or desktop app that acts for the person using itAuthorization code + PKCE
"Sign in with Sporty" — you just need to know who someone isAuthorization code + PKCE, with the openid scope
A server-to-server integration acting for a club, with no person presentClient credentials
A booking system keeping its diary in step with a club'sClient credentials, see Syncing bookings
An AI agent or MCP clientAuthorization code + PKCE, usually with dynamic registration

There is no password grant and no implicit grant. OAuth 2.1 removes both.

Endpoints

Everything lives on https://api.sporty.plus.

PurposeEndpoint
AuthorizationGET /oauth2/authorize
TokenPOST /oauth2/token
Revocation (RFC 7009)POST /oauth2/token/revoke
Dynamic registration (RFC 7591)POST /oauth2/register
UserInfoGET /oauth2/userinfo
JWKSGET /oauth2/jwks

Rather than hard-coding those, fetch one of the discovery documents:

curl https://api.sporty.plus/.well-known/openid-configuration
curl https://api.sporty.plus/.well-known/oauth-authorization-server
curl https://api.sporty.plus/.well-known/oauth-protected-resource

Where tokens work

An access token is spent on the partner API, https://api.sporty.plus/api/partner/v1.

It will not work anywhere else. In particular /api/v3, the API our own apps use, refuses OAuth tokens outright and answers 403 with a message saying so. That surface is authorised for people using our own interface, not for applications acting on their behalf, and letting a token in there would grant far more than any consent screen described.

Next