简体中文

Build on Ayalink without crossing trust boundaries

Use the public API and installation-scoped Webhooks, and learn the OAuth 2.0 PKCE/DPoP security boundary. OAuth contracts are now in the verified Reference; real app and production enablement still require platform approval. Every example fails honestly when an API or capability is unavailable.

Public integration paths

    End-to-end integration
    Move from platform enablement and authorization through API use, Webhooks, testing, production, and emergency revocation, with availability at every stage.
    Third-party Storefront
    Render public catalog data and send users through the Ayalink authorization domain for account access.
    OAuth and PKCE
    Official authorization domain, exact redirects, PKCE S256, isolated grants, and phishing recovery; OAuth APIs remain pending review.
    Runtime extensions
    Signed Webhooks, versioned inventory synchronization, and recoverable automatic fulfillment.
Copyright © 2026