SOLFIND
Web Lens
Portal home

Implicit Grant Flow | Spotify for Developers

https://developer.spotify.com/documentation/web-api/tutorials/implicit-flow • 280 KB fetched
Open original page


Implicit Grant Flow | Spotify for Developers Skip to content

* Documentation Documentation Products
* Web API

* Web Playback SDK

* Ads API

* iOS

* Android

* Embeds

* Commercial Hardware

* Open Access

* Spotify Soloist
Guidelines
* Design

* Accessibility

* Legal

* Community

0

* Documentation Documentation Products
* Web API

* Web Playback SDK

* Ads API

* iOS

* Android

* Embeds

* Commercial Hardware

* Open Access

* Spotify Soloist
Guidelines
* Design

* Accessibility

* Legal

* Community

Web API

* Overview

* Getting started

* Building with AI

* Concepts Concepts Concepts
* Access Token

* API calls

* Apps

* Authorization

* Redirect URIs

* Playlists

* Quota modes

* Rate limits

* Scopes

* Spotify URIs and IDs

* Track Relinking

* Tutorials Tutorials Tutorials
* Authorization code

* Authorization code PKCE

* Client credentials

* Implicit grant [Deprecated]

* Refreshing tokens

* Migration: Implicit grant to Authorization code

* Migration: Insecure redirect URI

* Migration: February 2026 Dev Mode Changes

* How-Tos How-Tos How-Tos
* Display your Spotify profile data in a web app

* Changelog Changelog Changelog
* July 2026

* May 2026

* March 2026

* February 2026

Reference
* Albums Albums Albums
* Get Album

* Get Several Albums

* Get Album Tracks

* Get User's Saved Albums

* Save Albums for Current User

* Remove Users' Saved Albums

* Check User's Saved Albums

* Get New Releases

* Artists Artists Artists
* Get Artist

* Get Several Artists

* Get Artist's Albums

* Get Artist's Top Tracks

* Get Artist's Related Artists

* Audiobooks Audiobooks Audiobooks
* Get an Audiobook

* Get Several Audiobooks

* Get Audiobook Chapters

* Get User's Saved Audiobooks

* Save Audiobooks for Current User

* Remove User's Saved Audiobooks

* Check User's Saved Audiobooks

* Categories Categories Categories
* Get Several Browse Categories

* Get Single Browse Category

* Chapters Chapters Chapters
* Get a Chapter

* Get Several Chapters

* Episodes Episodes Episodes
* Get Episode

* Get Several Episodes

* Get User's Saved Episodes

* Save Episodes for Current User

* Remove User's Saved Episodes

* Check User's Saved Episodes

* Genres Genres Genres
* Get Available Genre Seeds

* Library Library Library
* Save Items to Library

* Remove Items from Library

* Check User's Saved Items

* Markets Markets Markets
* Get Available Markets

* Player Player Player
* Get Playback State

* Transfer Playback

* Get Available Devices

* Get Currently Playing Track

* Start/Resume Playback

* Pause Playback

* Skip To Next

* Skip To Previous

* Seek To Position

* Set Repeat Mode

* Set Playback Volume

* Toggle Playback Shuffle

* Get Recently Played Tracks

* Get the User's Queue

* Add Item to Playback Queue

* Playlists Playlists Playlists
* Get Playlist

* Change Playlist Details

* Get Playlist Items [DEPRECATED]

* Update Playlist Items [DEPRECATED]

* Add Items to Playlist [DEPRECATED]

* Remove Playlist Items [DEPRECATED]

* Get Playlist Items

* Update Playlist Items

* Add Items to Playlist

* Remove Playlist Items

* Get Current User's Playlists

* Create Playlist

* Get User's Playlists

* Create Playlist for user

* Get Featured Playlists

* Get Category's Playlists

* Get Playlist Cover Image

* Add Custom Playlist Cover Image

* Search Search Search
* Search for Item

* Shows Shows Shows
* Get Show

* Get Several Shows

* Get Show Episodes

* Get User's Saved Shows

* Save Shows for Current User

* Remove User's Saved Shows

* Check User's Saved Shows

* Tracks Tracks Tracks
* Get Track

* Get Several Tracks

* Get User's Saved Tracks

* Save Tracks for Current User

* Remove User's Saved Tracks

* Check User's Saved Tracks

* Get Several Tracks' Audio Features

* Get Track's Audio Features

* Get Track's Audio Analysis

* Get Recommendations

* Users Users Users
* Get Current User's Profile

* Get User's Top Items

* Get User's Profile

* Follow Playlist

* Unfollow Playlist

* Get Followed Artists

* Follow Artists or Users

* Unfollow Artists or Users

* Check If User Follows Artists or Users

* Check if Current User Follows Playlist

Web API
* Overview

* Getting started

* Building with AI

* Concepts Concepts Concepts
* Access Token

* API calls

* Apps

* Authorization

* Redirect URIs

* Playlists

* Quota modes

* Rate limits

* Scopes

* Spotify URIs and IDs

* Track Relinking

* Tutorials Tutorials Tutorials
* Authorization code

* Authorization code PKCE

* Client credentials

* Implicit grant [Deprecated]

* Refreshing tokens

* Migration: Implicit grant to Authorization code

* Migration: Insecure redirect URI

* Migration: February 2026 Dev Mode Changes

* How-Tos How-Tos How-Tos
* Display your Spotify profile data in a web app

* Changelog Changelog Changelog
* July 2026

* May 2026

* March 2026

* February 2026

Reference
* Albums Albums Albums
* Get Album

* Get Several Albums

* Get Album Tracks

* Get User's Saved Albums

* Save Albums for Current User

* Remove Users' Saved Albums

* Check User's Saved Albums

* Get New Releases

* Artists Artists Artists
* Get Artist

* Get Several Artists

* Get Artist's Albums

* Get Artist's Top Tracks

* Get Artist's Related Artists

* Audiobooks Audiobooks Audiobooks
* Get an Audiobook

* Get Several Audiobooks

* Get Audiobook Chapters

* Get User's Saved Audiobooks

* Save Audiobooks for Current User

* Remove User's Saved Audiobooks

* Check User's Saved Audiobooks

* Categories Categories Categories
* Get Several Browse Categories

* Get Single Browse Category

* Chapters Chapters Chapters
* Get a Chapter

* Get Several Chapters

* Episodes Episodes Episodes
* Get Episode

* Get Several Episodes

* Get User's Saved Episodes

* Save Episodes for Current User

* Remove User's Saved Episodes

* Check User's Saved Episodes

* Genres Genres Genres
* Get Available Genre Seeds

* Library Library Library
* Save Items to Library

* Remove Items from Library

* Check User's Saved Items

* Markets Markets Markets
* Get Available Markets

* Player Player Player
* Get Playback State

* Transfer Playback

* Get Available Devices

* Get Currently Playing Track

* Start/Resume Playback

* Pause Playback

* Skip To Next

* Skip To Previous

* Seek To Position

* Set Repeat Mode

* Set Playback Volume

* Toggle Playback Shuffle

* Get Recently Played Tracks

* Get the User's Queue

* Add Item to Playback Queue

* Playlists Playlists Playlists
* Get Playlist

* Change Playlist Details

* Get Playlist Items [DEPRECATED]

* Update Playlist Items [DEPRECATED]

* Add Items to Playlist [DEPRECATED]

* Remove Playlist Items [DEPRECATED]

* Get Playlist Items

* Update Playlist Items

* Add Items to Playlist

* Remove Playlist Items

* Get Current User's Playlists

* Create Playlist

* Get User's Playlists

* Create Playlist for user

* Get Featured Playlists

* Get Category's Playlists

* Get Playlist Cover Image

* Add Custom Playlist Cover Image

* Search Search Search
* Search for Item

* Shows Shows Shows
* Get Show

* Get Several Shows

* Get Show Episodes

* Get User's Saved Shows

* Save Shows for Current User

* Remove User's Saved Shows

* Check User's Saved Shows

* Tracks Tracks Tracks
* Get Track

* Get Several Tracks

* Get User's Saved Tracks

* Save Tracks for Current User

* Remove User's Saved Tracks

* Check User's Saved Tracks

* Get Several Tracks' Audio Features

* Get Track's Audio Features

* Get Track's Audio Analysis

* Get Recommendations

* Users Users Users
* Get Current User's Profile

* Get User's Top Items

* Get User's Profile

* Follow Playlist

* Unfollow Playlist

* Get Followed Artists

* Follow Artists or Users

* Unfollow Artists or Users

* Check If User Follows Artists or Users

* Check if Current User Follows Playlist

Implicit Grant Flow

The Implicit Grant Flow will be sunset on November 27, 2025.

The implicit grant flow has some significant security flaws, so we strongly advise against using this flow. If you need to implement authorization where storing your client secret is not possible, use Authorization code with PKCE instead. If you are already using the implicit grant flow, we recommend reading this migration guide .

The implicit grant flow is carried out on the client side and it does not
involve secret keys. Thus, you do not need any server-side code to use it.
Access tokens issued are short-lived with no refresh token to extend them when
they expire.

The following diagram shows how the Implicit Grant Flow works:

Pre-requisites

This guide assumes that:

* You have read the authorization guide .

* You have created an app following the app guide .

Source Code

You can find an example app implementing Implicit Grant flow on GitHub in
the web-api-examples repository.

Request User Authorization

Our application must build a GET request to the /authorize endpoint with
the following parameters:

Query Parameter Relevance Value
client_id Required The client ID provided to you by Spotify when you register your application.
response_type Required Set it to token .
redirect_uri Required The URI to redirect to after the user grants or denies permission. This URI needs to have been entered in the Redirect URI allowlist that you specified when you registered your application (See the app guide ). The value of redirect_uri here must exactly match one of the values you entered when you registered your application, including upper or lowercase, terminating slashes, and such.
state Optional, but strongly recommended. The state can be useful for correlating requests and responses. Because your redirect_uri can be guessed, using a state value can increase your assurance that an incoming connection is the result of an authentication request. If you generate a random string or encode the hash of some client state (e.g., a cookie) in this state variable, you can validate the response to additionally ensure that the request and response originated in the same browser. This provides protection against attacks such as cross-site request forgery. See RFC-6749 .
scope Optional A space-separated list of scopes .
show_dialog Optional Whether or not to force the user to approve the app again if they’ve already done so. If false (default), a user who has already approved the application may be automatically redirected to the URI specified by redirect_uri . If true, the user will not be automatically redirected and will have to approve the app again.

The request is typically sent from the browser.

The following JavaScript sample builds the authorization request:

_ 14 var client_id = 'CLIENT_ID';

_ 14 var redirect_uri = 'http://127.0.0.1:8888/callback';

_ 14

_ 14 var state = generateRandomString(16);

_ 14

_ 14 localStorage.setItem(stateKey, state);

_ 14 var scope = 'user-read-private user-read-email';

_ 14

_ 14 var url = 'https://accounts.spotify.com/authorize';

_ 14 url += '?response_type=token';

_ 14 url += '&client_id=' + encodeURIComponent(client_id);

_ 14 url += '&scope=' + encodeURIComponent(scope);

_ 14 url += '&redirect_uri=' + encodeURIComponent(redirect_uri);

_ 14 url += '&state=' + encodeURIComponent(state);

Once the request is processed, the user will see the authorization dialog
asking to authorize access within the scopes.

The Spotify Accounts service presents details of the
scopes for which access
is being sought. If the user is not logged in, they are prompted to do so using
their Spotify credentials. When the user is logged in, they are asked to
authorize access to the resources or actions defined in the scopes.

Finally, the user is redirected back to your specified redirect_uri . After
the user accepts, or denies your request, the Spotify OAuth 2.0 server
redirects the user back to your redirect_uri . In this example, the redirect
address is https://127.0.0.1:8888/callback

Response

If the user grants access, the final URL will contain a hash fragment with
the following data encoded as a query string.

Query Parameter Value
access_token An access token that can be provided in subsequent calls, for example to Spotify Web API services.
token_type Value: "Bearer"
expires_in The time period (in seconds) for which the access token is valid.
state The value of the state parameter supplied in authorization URI.

For example:

_ 10 https://example.com/callback#access_token=NwAExz...BV3O2Tk&token_type=Bearer&expires_in=3600&state=123

If the user denies access, access token is not included and the final URL
includes a query string containing the following parameters:

Query Parameter Value
error The reason authorization failed, for example: "access_denied".
state The value of the state parameter supplied in the request.

For example:

_ 10 https://example.com/callback?error=access_denied&state=123

What's next?

Learn how to use an access token to fetch data from the Spotify Web API by reading the access token guide .

Footer
Documentation

* Web API

* Web Playback SDK

* Ads API

* iOS

* Android

* Embeds

* Commercial Hardware

Guidelines

* Design

* Accessibility

Community

* News

* Forum

Legal

* Developer Terms

* Developer Policy

* Compliance Tips

* Third Party Licenses

Legal Cookies © 2026 Spotify AB

Links found on this page

  1. Skip to content [direct]
  2. Web API [direct]
  3. Web Playback SDK [direct]
  4. Ads API [direct]
  5. iOS [direct]
  6. Android [direct]
  7. Embeds [direct]
  8. Commercial Hardware [direct]
  9. Open Access [direct]
  10. Spotify Soloist [direct]
  11. Design [direct]
  12. Accessibility [direct]
  13. Legal [direct]
  14. Community [direct]
  15. Getting started [direct]
  16. Building with AI [direct]
  17. Access Token [direct]
  18. API calls [direct]
  19. Apps [direct]
  20. Authorization [direct]
  21. Redirect URIs [direct]
  22. Playlists [direct]
  23. Quota modes [direct]
  24. Rate limits [direct]
  25. Scopes [direct]
  26. Spotify URIs and IDs [direct]
  27. Track Relinking [direct]
  28. Authorization code [direct]
  29. Authorization code PKCE [direct]
  30. Client credentials [direct]
  31. Refreshing tokens [direct]
  32. Migration: Implicit grant to Authorization code [direct]
  33. Migration: Insecure redirect URI [direct]
  34. Migration: February 2026 Dev Mode Changes [direct]
  35. Display your Spotify profile data in a web app [direct]
  36. July 2026 [direct]
  37. May 2026 [direct]
  38. March 2026 [direct]
  39. February 2026 [direct]
  40. Get Album [direct]
  41. Get Several Albums [direct]
  42. Get Album Tracks [direct]
  43. Get User's Saved Albums [direct]
  44. Save Albums for Current User [direct]
  45. Remove Users' Saved Albums [direct]
  46. Check User's Saved Albums [direct]
  47. Get New Releases [direct]
  48. Get Artist [direct]
  49. Get Several Artists [direct]
  50. Get Artist's Albums [direct]
  51. Get Artist's Top Tracks [direct]
  52. Get Artist's Related Artists [direct]
  53. Get an Audiobook [direct]
  54. Get Several Audiobooks [direct]
  55. Get Audiobook Chapters [direct]
  56. Get User's Saved Audiobooks [direct]
  57. Save Audiobooks for Current User [direct]
  58. Remove User's Saved Audiobooks [direct]
  59. Check User's Saved Audiobooks [direct]
  60. Get Several Browse Categories [direct]
  61. Get Single Browse Category [direct]
  62. Get a Chapter [direct]
  63. Get Several Chapters [direct]
  64. Get Episode [direct]
  65. Get Several Episodes [direct]
  66. Get User's Saved Episodes [direct]
  67. Save Episodes for Current User [direct]
  68. Remove User's Saved Episodes [direct]
  69. Check User's Saved Episodes [direct]
  70. Get Available Genre Seeds [direct]
  71. Save Items to Library [direct]
  72. Remove Items from Library [direct]
  73. Check User's Saved Items [direct]
  74. Get Available Markets [direct]
  75. Get Playback State [direct]
  76. Transfer Playback [direct]
  77. Get Available Devices [direct]
  78. Get Currently Playing Track [direct]
  79. Start/Resume Playback [direct]
  80. Pause Playback [direct]