Migrate from Implicit Grant Flow to Authorization Code with PKCE | Spotify for Developers
https://developer.spotify.com/documentation/web-api/tutorials/migration-implicit-auth-code • 275 KB fetched Open original page
Migrate from Implicit Grant Flow to Authorization Code with PKCE | Spotify for Developers Skip to content
* Documentation Documentation Products
* Web API
* Web Playback SDK
* Ads API
* iOS
* Android
* Embeds
* Commercial Hardware
* Open Access
* Spotify Soloist
Guidelines
* Design
* Accessibility
* Legal
* Community
0
* Documentation Documentation Products
* Web API
* Web Playback SDK
* Ads API
* iOS
* Android
* Embeds
* Commercial Hardware
* Open Access
* Spotify Soloist
Guidelines
* Design
* Accessibility
* Legal
* Community
Web API
* Overview
* Getting started
* Building with AI
* Concepts Concepts Concepts
* Access Token
* API calls
* Apps
* Authorization
* Redirect URIs
* Playlists
* Quota modes
* Rate limits
* Scopes
* Spotify URIs and IDs
* Track Relinking
* Tutorials Tutorials Tutorials
* Authorization code
* Authorization code PKCE
* Client credentials
* Implicit grant [Deprecated]
* Refreshing tokens
* Migration: Implicit grant to Authorization code
* Migration: Insecure redirect URI
* Migration: February 2026 Dev Mode Changes
* How-Tos How-Tos How-Tos
* Display your Spotify profile data in a web app
* Changelog Changelog Changelog
* July 2026
* May 2026
* March 2026
* February 2026
Reference
* Albums Albums Albums
* Get Album
* Get Several Albums
* Get Album Tracks
* Get User's Saved Albums
* Save Albums for Current User
* Remove Users' Saved Albums
* Check User's Saved Albums
* Get New Releases
* Artists Artists Artists
* Get Artist
* Get Several Artists
* Get Artist's Albums
* Get Artist's Top Tracks
* Get Artist's Related Artists
* Audiobooks Audiobooks Audiobooks
* Get an Audiobook
* Get Several Audiobooks
* Get Audiobook Chapters
* Get User's Saved Audiobooks
* Save Audiobooks for Current User
* Remove User's Saved Audiobooks
* Check User's Saved Audiobooks
* Categories Categories Categories
* Get Several Browse Categories
* Get Single Browse Category
* Chapters Chapters Chapters
* Get a Chapter
* Get Several Chapters
* Episodes Episodes Episodes
* Get Episode
* Get Several Episodes
* Get User's Saved Episodes
* Save Episodes for Current User
* Remove User's Saved Episodes
* Check User's Saved Episodes
* Genres Genres Genres
* Get Available Genre Seeds
* Library Library Library
* Save Items to Library
* Remove Items from Library
* Check User's Saved Items
* Markets Markets Markets
* Get Available Markets
* Player Player Player
* Get Playback State
* Transfer Playback
* Get Available Devices
* Get Currently Playing Track
* Start/Resume Playback
* Pause Playback
* Skip To Next
* Skip To Previous
* Seek To Position
* Set Repeat Mode
* Set Playback Volume
* Toggle Playback Shuffle
* Get Recently Played Tracks
* Get the User's Queue
* Add Item to Playback Queue
* Playlists Playlists Playlists
* Get Playlist
* Change Playlist Details
* Get Playlist Items [DEPRECATED]
* Update Playlist Items [DEPRECATED]
* Add Items to Playlist [DEPRECATED]
* Remove Playlist Items [DEPRECATED]
* Get Playlist Items
* Update Playlist Items
* Add Items to Playlist
* Remove Playlist Items
* Get Current User's Playlists
* Create Playlist
* Get User's Playlists
* Create Playlist for user
* Get Featured Playlists
* Get Category's Playlists
* Get Playlist Cover Image
* Add Custom Playlist Cover Image
* Search Search Search
* Search for Item
* Shows Shows Shows
* Get Show
* Get Several Shows
* Get Show Episodes
* Get User's Saved Shows
* Save Shows for Current User
* Remove User's Saved Shows
* Check User's Saved Shows
* Tracks Tracks Tracks
* Get Track
* Get Several Tracks
* Get User's Saved Tracks
* Save Tracks for Current User
* Remove User's Saved Tracks
* Check User's Saved Tracks
* Get Several Tracks' Audio Features
* Get Track's Audio Features
* Get Track's Audio Analysis
* Get Recommendations
* Users Users Users
* Get Current User's Profile
* Get User's Top Items
* Get User's Profile
* Follow Playlist
* Unfollow Playlist
* Get Followed Artists
* Follow Artists or Users
* Unfollow Artists or Users
* Check If User Follows Artists or Users
* Check if Current User Follows Playlist
Web API
* Overview
* Getting started
* Building with AI
* Concepts Concepts Concepts
* Access Token
* API calls
* Apps
* Authorization
* Redirect URIs
* Playlists
* Quota modes
* Rate limits
* Scopes
* Spotify URIs and IDs
* Track Relinking
* Tutorials Tutorials Tutorials
* Authorization code
* Authorization code PKCE
* Client credentials
* Implicit grant [Deprecated]
* Refreshing tokens
* Migration: Implicit grant to Authorization code
* Migration: Insecure redirect URI
* Migration: February 2026 Dev Mode Changes
* How-Tos How-Tos How-Tos
* Display your Spotify profile data in a web app
* Changelog Changelog Changelog
* July 2026
* May 2026
* March 2026
* February 2026
Reference
* Albums Albums Albums
* Get Album
* Get Several Albums
* Get Album Tracks
* Get User's Saved Albums
* Save Albums for Current User
* Remove Users' Saved Albums
* Check User's Saved Albums
* Get New Releases
* Artists Artists Artists
* Get Artist
* Get Several Artists
* Get Artist's Albums
* Get Artist's Top Tracks
* Get Artist's Related Artists
* Audiobooks Audiobooks Audiobooks
* Get an Audiobook
* Get Several Audiobooks
* Get Audiobook Chapters
* Get User's Saved Audiobooks
* Save Audiobooks for Current User
* Remove User's Saved Audiobooks
* Check User's Saved Audiobooks
* Categories Categories Categories
* Get Several Browse Categories
* Get Single Browse Category
* Chapters Chapters Chapters
* Get a Chapter
* Get Several Chapters
* Episodes Episodes Episodes
* Get Episode
* Get Several Episodes
* Get User's Saved Episodes
* Save Episodes for Current User
* Remove User's Saved Episodes
* Check User's Saved Episodes
* Genres Genres Genres
* Get Available Genre Seeds
* Library Library Library
* Save Items to Library
* Remove Items from Library
* Check User's Saved Items
* Markets Markets Markets
* Get Available Markets
* Player Player Player
* Get Playback State
* Transfer Playback
* Get Available Devices
* Get Currently Playing Track
* Start/Resume Playback
* Pause Playback
* Skip To Next
* Skip To Previous
* Seek To Position
* Set Repeat Mode
* Set Playback Volume
* Toggle Playback Shuffle
* Get Recently Played Tracks
* Get the User's Queue
* Add Item to Playback Queue
* Playlists Playlists Playlists
* Get Playlist
* Change Playlist Details
* Get Playlist Items [DEPRECATED]
* Update Playlist Items [DEPRECATED]
* Add Items to Playlist [DEPRECATED]
* Remove Playlist Items [DEPRECATED]
* Get Playlist Items
* Update Playlist Items
* Add Items to Playlist
* Remove Playlist Items
* Get Current User's Playlists
* Create Playlist
* Get User's Playlists
* Create Playlist for user
* Get Featured Playlists
* Get Category's Playlists
* Get Playlist Cover Image
* Add Custom Playlist Cover Image
* Search Search Search
* Search for Item
* Shows Shows Shows
* Get Show
* Get Several Shows
* Get Show Episodes
* Get User's Saved Shows
* Save Shows for Current User
* Remove User's Saved Shows
* Check User's Saved Shows
* Tracks Tracks Tracks
* Get Track
* Get Several Tracks
* Get User's Saved Tracks
* Save Tracks for Current User
* Remove User's Saved Tracks
* Check User's Saved Tracks
* Get Several Tracks' Audio Features
* Get Track's Audio Features
* Get Track's Audio Analysis
* Get Recommendations
* Users Users Users
* Get Current User's Profile
* Get User's Top Items
* Get User's Profile
* Follow Playlist
* Unfollow Playlist
* Get Followed Artists
* Follow Artists or Users
* Unfollow Artists or Users
* Check If User Follows Artists or Users
* Check if Current User Follows Playlist
Migrate from Implicit Grant Flow to Authorization Code with PKCE
Since we are deprecating the Implicit Grant Flow, you should migrate your application to use the Authorization Code with PKCE flow.
This guide will help you migrate complete the migration for a Web Application.
Prerequisites
This guide assumes that:
* You have read the authorization guide .
* You have created an app following the app guide .
* You have read the Authorization Code with PKCE guide.
Migrate from Implicit Grant Flow to Authorization Code with PKCE
Step 1: Update your app to use Authorization Code with PKCE
The first step of this migration is to find the code that calls the /authorize endpoint with the token response type.
You should replace the token response type with code and add the code_challenge and code_challenge_method parameters.
For instance, let's say you have the following code:
_ 14 var client_id = 'CLIENT_ID';
_ 14 var redirect_uri = 'http://127.0.0.1:8888/callback';
_ 14
_ 14 var state = generateRandomString(16);
_ 14
_ 14 localStorage.setItem(stateKey, state);
_ 14 var scope = 'user-read-private user-read-email';
_ 14
_ 14 var url = 'https://accounts.spotify.com/authorize';
_ 14 url += '?response_type=token';
_ 14 url += '&client_id=' + encodeURIComponent(client_id);
_ 14 url += '&scope=' + encodeURIComponent(scope);
_ 14 url += '&redirect_uri=' + encodeURIComponent(redirect_uri);
_ 14 url += '&state=' + encodeURIComponent(state);
you need to update it to:
_ 20 const clientId = 'YOUR_CLIENT_ID';
_ 20 const redirectUri = 'http://127.0.0.1:8080';
_ 20
_ 20 const scope = 'user-read-private user-read-email';
_ 20 const authUrl = new URL("https://accounts.spotify.com/authorize")
_ 20
_ 20 // generated in the previous step
_ 20 window.localStorage.setItem('code_verifier', codeVerifier);
_ 20
_ 20 const params = {
_ 20 response_type: 'code',
_ 20 client_id: clientId,
_ 20 scope,
_ 20 code_challenge_method: 'S256',
_ 20 code_challenge: codeChallenge,
_ 20 redirect_uri: redirectUri
_ 20 }
_ 20
_ 20 authUrl.search = new URLSearchParams(params).toString();
_ 20 window.location.href = authUrl.toString();
As you can see there is quite a difference between the two code snippets.
The new code snippet generates a PKCE code challenge and redirects to the Spotify authorization server login page by updating the window.location object value.
If you are not familiar with PKCE, you can read more about it in the Authorization Code with PKCE guide.
Step 2: Handle the authorization code
After the user grants permissions to your application, the Spotify authorization server will redirect the user back to the URL specified in the redirect_uri field.
This is similar to the Implicit Grant Flow, but the response will contain an authorization code instead of an access token .
Now you need to exchange the authorization code for an access token .
To do this, you need to parse the URL to retrieve the code parameter:
_ 10 const urlParams = new URLSearchParams(window.location.search);
_ 10 let code = urlParams.get('code');
The code will be necessary to request the access token in the next step.
Step 3: Request the access token (and refresh token)
The last step is to request the access token using the authorization code you received in the previous step.
You can follow the steps in the Authorization Code with PKCE guide to request the access token.
Bear in mind that the access token you receive will have a refresh token.
While the refresh token remains valid, you can use it to get a new access token without repeating the authorization process. Refresh tokens expire, so
your app must also be able to request user authorization again.
If you want to know more about refresh tokens, you can read the refresh token guide .
Footer
Documentation
* Web API
* Web Playback SDK
* Ads API
* iOS
* Android
* Embeds
* Commercial Hardware
Guidelines
* Design
* Accessibility
Community
* News
* Forum
Legal
* Developer Terms
* Developer Policy
* Compliance Tips
* Third Party Licenses
Legal Cookies © 2026 Spotify AB
Links found on this page
- Skip to content [direct]
- Web API [direct]
- Web Playback SDK [direct]
- Ads API [direct]
- iOS [direct]
- Android [direct]
- Embeds [direct]
- Commercial Hardware [direct]
- Open Access [direct]
- Spotify Soloist [direct]
- Design [direct]
- Accessibility [direct]
- Legal [direct]
- Community [direct]
- Getting started [direct]
- Building with AI [direct]
- Access Token [direct]
- API calls [direct]
- Apps [direct]
- Authorization [direct]
- Redirect URIs [direct]
- Playlists [direct]
- Quota modes [direct]
- Rate limits [direct]
- Scopes [direct]
- Spotify URIs and IDs [direct]
- Track Relinking [direct]
- Authorization code [direct]
- Authorization code PKCE [direct]
- Client credentials [direct]
- Implicit grant [Deprecated] [direct]
- Refreshing tokens [direct]
- Migration: Insecure redirect URI [direct]
- Migration: February 2026 Dev Mode Changes [direct]
- Display your Spotify profile data in a web app [direct]
- July 2026 [direct]
- May 2026 [direct]
- March 2026 [direct]
- February 2026 [direct]
- Get Album [direct]
- Get Several Albums [direct]
- Get Album Tracks [direct]
- Get User's Saved Albums [direct]
- Save Albums for Current User [direct]
- Remove Users' Saved Albums [direct]
- Check User's Saved Albums [direct]
- Get New Releases [direct]
- Get Artist [direct]
- Get Several Artists [direct]
- Get Artist's Albums [direct]
- Get Artist's Top Tracks [direct]
- Get Artist's Related Artists [direct]
- Get an Audiobook [direct]
- Get Several Audiobooks [direct]
- Get Audiobook Chapters [direct]
- Get User's Saved Audiobooks [direct]
- Save Audiobooks for Current User [direct]
- Remove User's Saved Audiobooks [direct]
- Check User's Saved Audiobooks [direct]
- Get Several Browse Categories [direct]
- Get Single Browse Category [direct]
- Get a Chapter [direct]
- Get Several Chapters [direct]
- Get Episode [direct]
- Get Several Episodes [direct]
- Get User's Saved Episodes [direct]
- Save Episodes for Current User [direct]
- Remove User's Saved Episodes [direct]
- Check User's Saved Episodes [direct]
- Get Available Genre Seeds [direct]
- Save Items to Library [direct]
- Remove Items from Library [direct]
- Check User's Saved Items [direct]
- Get Available Markets [direct]
- Get Playback State [direct]
- Transfer Playback [direct]
- Get Available Devices [direct]
- Get Currently Playing Track [direct]
- Start/Resume Playback [direct]
- Pause Playback [direct]
|
|