Skip to content

Instantly share code, notes, and snippets.

Last active June 29, 2021 09:55
Show Gist options
  • Save westc/d4ed9d82f0909e3614979490d1428bf2 to your computer and use it in GitHub Desktop.
Save westc/d4ed9d82f0909e3614979490d1428bf2 to your computer and use it in GitHub Desktop.
Simple PHP example of using Github's OAuth 2 API to make a login
define('OAUTH2_CLIENT_ID', '');
define('OAUTH2_CLIENT_SECRET', '');
$authorizeURL = '';
$tokenURL = '';
$apiURLBase = '';
// Start the login process by sending the user to Github's authorization page
if(get('action') == 'login') {
// Generate a random hash and store in the session for security
$_SESSION['state'] = hash('sha256', microtime(TRUE) . rand() . $_SERVER['REMOTE_ADDR']);
// Redirect the user to Github's authorization page
redirect_to($authorizeURL . '?' . http_build_query([
'client_id' => OAUTH2_CLIENT_ID,
'redirect_uri' => get_current_base_url(),
'state' => $_SESSION['state'],
'scope' => 'user:email'
// When Github redirects the user back here, there will be a "code" and "state" parameter in the query string
if(get('code')) {
// Verify the state matches our stored state
if(!get('state') || $_SESSION['state'] != get('state')) {
// Exchange the auth code for a token
$token = apiRequest($tokenURL . '?' . http_build_query([
'client_id' => OAUTH2_CLIENT_ID,
'client_secret' => OAUTH2_CLIENT_SECRET,
'state' => session('state'),
'code' => get('code')
$_SESSION['access_token'] = $token->access_token;
if(session('access_token')) {
$user = apiRequest($apiURLBase . 'user?access_token=' . session('access_token'));
echo '<h3>Logged In</h3>';
echo '<h4>' . $user->name . '</h4>';
echo '<pre>';
echo '</pre>';
} else {
echo '<h3>Not logged in</h3>';
echo '<p><a href="?action=login">Log In</a></p>';
function apiRequest($url) {
$context = stream_context_create([
'http' => [
'user_agent' => 'CWestify GitHub OAuth Login',
'header' => 'Accept: application/json'
$response = @file_get_contents($url, false, $context);
return $response ? json_decode($response) : $response;
function get($key, $default=NULL) {
return isset($_GET[$key]) ? $_GET[$key] : $default;
function session($key, $default=NULL) {
return isset($_SESSION[$key]) ? $_SESSION[$key] : $default;
function get_current_base_url() {
return get_site_url() . preg_replace('/\?.*/', '', $_SERVER['REQUEST_URI']);
function get_site_url() {
return 'http' . ($_SERVER["HTTPS"] ? 's' : '')
. "://{$_SERVER['SERVER_NAME']}"
. ($_SERVER["SERVER_PORT"] !== '80' ? ":{$_SERVER['SERVER_PORT']}" : '');
function redirect_to($url) {
header('Location: ' . $url);
Copy link

westc commented Jul 7, 2017

This blog post briefly outlines how to use this code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment