> ## Documentation Index
> Fetch the complete documentation index at: https://developers.pleo.io/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth 2.0 Client Configuration

> Configuring your application to work with Pleo authorization server

export const WarningCallout = ({title, children}) => <div className="callout-box callout-warning">
    <div className="callout-row">
      <span className="callout-badge">
        <svg width="18" height="18" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 256 256" fill="currentColor"><path d="M215.46,216H40.54C27.92,216,20,202.79,26.13,192.09L113.59,40.22c6.3-11,22.52-11,28.82,0l87.46,151.87C236,202.79,228.08,216,215.46,216Z" opacity="0.2" /><path d="M236.8,188.09,149.35,36.22h0a24.76,24.76,0,0,0-42.7,0L19.2,188.09a23.51,23.51,0,0,0,0,23.72A24.35,24.35,0,0,0,40.55,224h174.9a24.35,24.35,0,0,0,21.33-12.19A23.51,23.51,0,0,0,236.8,188.09ZM222.93,203.8a8.5,8.5,0,0,1-7.48,4.2H40.55a8.5,8.5,0,0,1-7.48-4.2,7.59,7.59,0,0,1,0-7.72L120.52,44.21a8.75,8.75,0,0,1,15,0l87.45,151.87A7.59,7.59,0,0,1,222.93,203.8ZM120,144V104a8,8,0,0,1,16,0v40a8,8,0,0,1-16,0Zm20,36a12,12,0,1,1-12-12A12,12,0,0,1,140,180Z" /></svg>
      </span>
      <div>
        {title && <div className="callout-title">
            {title}
          </div>}
        <div className="callout-body">
          {children}
        </div>
      </div>
    </div>
  </div>;

<WarningCallout title="This page has now been ARCHIVED. Please visit:">
  * **[OAuth 2.0 Setup Workflow Guide](/docs/current/guides/oauth-workflow-guide)**
</WarningCallout>

After registering the OAuth 2.0 client, configure it using the information provided below.

| Parameter              | Value                                                                                 |
| :--------------------- | :------------------------------------------------------------------------------------ |
| Authorization Endpoint | `{AUTHORIZATION_SERVER_URL}/oauth/authorize`                                          |
| Token Endpoint         | `{AUTHORIZATION_SERVER_URL}/oauth/token`                                              |
| Grant Type             | Authorization code grant, with PKCE extension.                                        |
| Client Credentials     | Client identifier and client secret of your client.                                   |
| Client Authentication  | Only `client_secret_basic` client authentication method is supported.                 |
| Redirect URI           | URI of a redirection endpoint used by your client.                                    |
| PKCE                   | Required, if supported by the client. Only `S256` code challenge method is supported. |

Exact mapping between these parameters and the configuration options provided by OAuth 2.0 client implementation, depend on the choice of the the software. Consult the documentation provided by your chosen implementation of OAuth 2.0 client.

## Authorisation Server URL

When configuring authorisation and token endpoints, substitute `{AUTHORIZATION_SERVER_URL}` with the base URL of the authorisation server in the environment that you’re developing for.

| Environment | Authorization Server URL       |
| :---------- | :----------------------------- |
| Staging     | `https://auth.staging.pleo.io` |
| Production  | `https://auth.pleo.io`         |
