Comick Developers
Comick Developers
Catalog APIMy appsBack to ComickBuild with Comick

Getting started

Register your appApp review
Backend quickstartBrowser quickstartMobile quickstart

API reference

OAuth referenceRefresh and disconnectLibrary APIErrors and limits
Quickstarts

Backend quickstart

Connect a confidential server application using Authorization Code and PKCE.

Register a confidential app and store its client ID and secret on your backend. The examples use Node.js and the Fetch API. Replace example domains with your registered callback.

1. Create an authorization attempt

Generate fresh state and verifier values for every attempt. Store them in a short-lived record tied to the signed-in user of your application, using a secure, HttpOnly, SameSite=Lax session cookie. Expire the attempt after ten minutes and consume it once on callback.

import { createHash, randomBytes } from "node:crypto"

const clientId = process.env.COMICK_CLIENT_ID!
const redirectUri = "https://your-app.example/oauth/comick/callback"
const resource = "https://api.comick.dev/integrations/v1"
const state = randomBytes(32).toString("base64url")
const verifier = randomBytes(32).toString("base64url")
const challenge = createHash("sha256").update(verifier).digest("base64url")

const authorize = new URL("https://comick.dev/api/auth/oauth2/authorize")
authorize.search = new URLSearchParams({
  response_type: "code",
  client_id: clientId,
  redirect_uri: redirectUri,
  scope: "library:read offline_access",
  resource,
  state,
  code_challenge: challenge,
  code_challenge_method: "S256",
}).toString()
// Persist { state, verifier, redirectUri, createdAt } in this user's session.
// Redirect the user's browser to authorize.toString().

Omit offline_access if you do not need continued synchronization. Comick handles sign-in and consent.

2. Validate the callback

On your callback route, retrieve and consume the attempt from the initiating session. Reject missing, expired, duplicate, or mismatched state values before using the code or handling a denial. Do not accept a callback for a different application user.

If the validated callback contains error=access_denied, show “Connection cancelled.” Otherwise require exactly one code, and exchange it once. Remove callback parameters from the browser URL after handling them.

3. Exchange the code on your server

Use HTTP Basic client authentication and a form-encoded request. This example assumes code and attempt have passed the callback checks above.

const basic = Buffer.from(
  `${encodeURIComponent(clientId)}:${encodeURIComponent(process.env.COMICK_CLIENT_SECRET!)}`,
).toString("base64")
const response = await fetch("https://comick.dev/api/auth/oauth2/token", {
  method: "POST",
  headers: {
    Authorization: `Basic ${basic}`,
    "Content-Type": "application/x-www-form-urlencoded",
  },
  body: new URLSearchParams({
    grant_type: "authorization_code",
    code,
    redirect_uri: attempt.redirectUri,
    code_verifier: attempt.verifier,
    resource,
  }),
})
if (!response.ok) throw new Error(`Comick exchange failed: ${response.status}`)
const tokens = await response.json()
// Encrypt tokens in server storage, bound to this application user.
// Do not send refresh tokens or your client secret to the browser.

Save access_token, expires_in, the granted scope, and refresh_token when present. The user may decline offline access, so a refresh token is not guaranteed. Treat tokens as opaque strings.

4. Fetch the library

const response = await fetch(
  "https://api.comick.dev/integrations/v1/me/library",
  {
    headers: { Authorization: `Bearer ${tokens.access_token}` },
    cache: "no-store",
  },
)
if (!response.ok) throw new Error(`Comick library failed: ${response.status}`)
const library = await response.json()

Use the pagination loop in the library guide to load all followed titles. Add refresh and disconnect handling before inviting users, and submit for review.

App review

Request access for other users and understand how changes are reviewed.

Browser quickstart

Use a public client with PKCE, registered origins, and no client secret.

On this page

1. Create an authorization attempt2. Validate the callback3. Exchange the code on your server4. Fetch the library