miner

Exchange Chutes PKCE auth code for a refresh token (server-side)

Complete the Chutes OAuth code exchange on behalf of the SDK CLI.

Chutes' OAuth app is registered as a Confidential client (requires client_secret at /idp/token). The SDK, distributed via PyPI, can't safely hold a secret. So the SDK runs the browser PKCE leg locally (preserves auth-code interception protection) and then hands the resulting authorization code + code_verifier here. Backend holds the client_secret and completes the exchange (ORO-1463).

post/v1/miner/chutes/exchange-code

Request body

codestring required

Authorization code from Chutes /idp/authorize redirect.

code_verifierstring required

PKCE code_verifier the SDK generated before /idp/authorize. Per RFC 7636: 43–128 characters from the unreserved set [A-Za-z0-9-._~].

redirect_uristring required

Must exactly match the redirect_uri the SDK sent to /idp/authorize (per RFC 6749 §4.1.3). Backend validates against an allowlist.

Response

Successful Response

okboolean required

True on successful exchange + persistence.

default_providerstring nullable

Miner's default inference provider after persistence. Set to 'chutes' if this was the miner's first provider connection.

Changes

No recorded changes to this endpoint across all 1 revision of this API.