Get OAuth Status
GET/api/temu/oauth/status
Polled by the frontend after the OAuth popup/redirect to learn the state of the OAuth session.
Any valid API token can call this endpoint — no specific scope required. Manage tokens.
Used to determine whether Temu has called back yet, and what the next action is (e.g. proceed to /oauth/complete, or show a reconnection success toast).
Query parameters:
state(string, required) — The state returned byoauth/initialize.
Response data (always returned with HTTP 200):
found(bool) —falsewhen state is missing, expired, or unknown. The remaining fields are omitted in that case (onlymessageis present).completed(bool) —trueonce/oauth/completeor a reconnection has marked the session as done.has_code(bool) —trueonce the OAuth callback endpoint has received Temu's redirect and stored the authorization code in cache. The frontend uses this to know it's safe to call/oauth/complete.name(string|null) — The display name the user picked at/oauth/initialize.message(string, only onfound: false) — Human-readable reason (missing parameter or expired session).
Authentication: Bearer token (Sanctum).
Request
Responses
- 200
- 401
- 403
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.