Exchange Alza OAuth code
auth_exchangeExchange the OAuth 2.0 PKCE authorization code from the browser sign-in for Alza mobile API tokens, then load them into the server so account tools work.
Instructions
Complete the OAuth 2.0 PKCE sign-in: exchange the authorization code for mobile API tokens and load them into this server. Use immediately after the user finishes the auth_start flow in the browser. Pass the whole alza://identity?code=...&state=... redirect URL as code (state is then read from it), or the bare code plus state — never a password and never a refresh token here. Fails if the state does not match a pending auth_start session (start over from auth_start in that case). Side effect: replaces the token set currently loaded in this process; afterwards account tools such as cart, profile, and order are authenticated.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| code | Yes | Authorization code from the `alza://identity` redirect (the `code` query parameter), or the full redirect URL. | |
| state | No | State value returned by `auth_start`; must match the pending PKCE session exactly. Optional when `code` is the full redirect URL. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| err | No | ||
| msg | No | ||
| data | No |