Here’s a step-by-step guide:
​
PKCE Guide
​
Step 1: Send your user to OpenRouter
To start the PKCE flow, send your user to OpenRouter’s
/auth
URL with a
callback_url
parameter pointing back to your site:
With S256 Code Challenge (Recommended)
With Plain Code Challenge
Without Code Challenge
https://openrouter.ai/auth?callback_url=<YOUR_SITE_URL>&code_challenge=<CODE_CHALLENGE>&code_challenge_method=S256
https://openrouter.ai/auth?callback_url=<YOUR_SITE_URL>&code_challenge=<CODE_CHALLENGE>&code_challenge_method=plain
https://openrouter.ai/auth?callback_url=<YOUR_SITE_URL>
The
code_challenge
parameter is optional but recommended.
Your user will be prompted to log in to OpenRouter and authorize your app.

When moving to production, replace the localhost callback URL with a public URL (your project website or a GitHub repo link) to get full app attribution.
​
Headless Apps (SSH Servers, Containers)
If your app runs where a localhost callback can’t be reached (an SSH session, a remote dev box, a container), omit
callback_url
entirely:
Headless (No Callback)
https://openrouter.ai/auth?code_challenge=<CODE_CHALLENGE>&code_challenge_method=S256&key_label=<YOUR_APP_NAME>
After the user authorizes, the page displays the authorization code on screen instead of redirecting. The user copies it and pastes it into your app (e.g. at a terminal prompt), and you exchange it in Step 2 exactly as usual.
