Skip to content

Authentication ​

Milkloud supports OpenID Connect for applications and User Tokens for personal automation. Both methods issue scoped credentials. Request only the scopes that the integration needs.

OpenID Connect ​

Use a maintained OpenID Connect client library to integrate with Milkloud.

Discovery ​

ServiceDiscovery document
Chinahttps://milkloud.milthm.cn/api/oidc/.well-known/openid-configuration
Globalhttps://milkloud.milthm.com/api/oidc/.well-known/openid-configuration

Configure the library with the discovery document for the service the user accesses. Do not hard-code individual OIDC endpoints.

Client Registration ​

OIDC clients are registered through manual review. Contact the Milthm team before implementing production sign-in and provide the application name, intended use, exact redirect URIs, application type, and required scopes.

Authorization Code Flow ​

Use Authorization Code flow. Milkloud clients use a client secret. Server-side clients that can keep the secret confidential may use the flow without PKCE. Native applications and browser-based SPAs must also use PKCE, even when the client secret is stored in the application. Follow the client library's documentation for the standard flow.

Send the resulting access token to Milkloud APIs as a Bearer token:

http
Authorization: Bearer ACCESS_TOKEN

See Scopes for available permissions and Authentication Errors for access-token recovery rules.

User Token ​

A User Token is a long-lived credential created by a Milkloud user for a personal script or trusted private tool. It is not an OIDC access token and does not use the Bearer scheme.

Create a Token ​

  1. Sign in to Milkloud.
  2. Open Settings, then Tokens.
  3. Complete password reauthentication when prompted.
  4. Choose a note, an expiration time, and only the scopes needed by the tool.
  5. Store the generated credential immediately. The secret is displayed only once.

The expiration must be in the future and cannot be more than 365 days from creation. Revoke a token from the same settings page when it is no longer needed or may have been exposed.

See Scopes for the capabilities available to a User Token.

Use a Token ​

The token screen provides a ready-to-use Authorization header:

http
Authorization: Basic BASE64_CREDENTIAL

Keep the full header in a secret manager or protected environment variable. Do not print it in build output or error logs.