Abbreviated from
Step 1: Begin authorization
Send the user to this web page, with your values filled in:<app key>&response_type=code&redirect_uri=<redirect URI>&state=<CSRF token>
The authorization code will be included as the code
parameter on the redirect URI.
Step 2: Obtain an access token
curl -d code=<authorization code> -d grant_type=authorization_code -d redirect_uri=<redirect URI> -u <app key>:<app secret>
Step 3: Call the API
In your API call, set the header:
Authorization: Bearer <access token>
Check out the blog post for more details, including an important security note on using state
to protect against CSRF attacks.