Authentication
Milkloud supports OpenID Connect for applications and User Tokens for personal automation. Both methods issue scoped credentials. Request only the scopes that the integration needs.
OpenID Connect
Use a maintained OpenID Connect client library to integrate with Milkloud.
Discovery
| Service | Discovery document |
|---|---|
| China | https://milkloud.milthm.cn/api/oidc/.well-known/openid-configuration |
| Global | https://milkloud.milthm.com/api/oidc/.well-known/openid-configuration |
Configure the library with the discovery document for the service the user accesses. Do not hard-code individual OIDC endpoints.
Client Registration
OIDC clients are registered through manual review. Contact the Milthm team before implementing production sign-in and provide the application name, intended use, exact redirect URIs, application type, and required scopes.
Authorization Code Flow
Use Authorization Code flow. Milkloud clients use a client secret. Server-side clients that can keep the secret confidential may use the flow without PKCE. Native applications and browser-based SPAs must also use PKCE, even when the client secret is stored in the application. Follow the client library's documentation for the standard flow.
Send the resulting access token to Milkloud APIs as a Bearer token:
Authorization: Bearer ACCESS_TOKENSee Scopes for available permissions and Authentication Errors for access-token recovery rules.
User Token
A User Token is a long-lived credential created by a Milkloud user for a personal script or trusted private tool. It is not an OIDC access token and does not use the Bearer scheme.
Create a Token
- Sign in to Milkloud.
- Open Settings, then Tokens.
- Complete password reauthentication when prompted.
- Choose a note, an expiration time, and only the scopes needed by the tool.
- Store the generated credential immediately. The secret is displayed only once.
The expiration must be in the future and cannot be more than 365 days from creation. Revoke a token from the same settings page when it is no longer needed or may have been exposed.
See Scopes for the capabilities available to a User Token.
Use a Token
The token screen provides a ready-to-use Authorization header:
Authorization: Basic BASE64_CREDENTIALKeep the full header in a secret manager or protected environment variable. Do not print it in build output or error logs.