MyAds

登录 报名

集成指南

开发者指南

通过分步说明和代码示例,掌握将 MyAds 集成到您的数字生态系统中。

1

创建您的应用程序

在开发人员仪表板中定义您的应用程序名称、域和重定向 URI,以接收您唯一的客户端 ID 和密钥。

信息: 在提交应用程序以供审核之前,准备好您的公共域、回调 URL 和请求的范围。

客户ID A unique 32-character hexadecimal identifier generated for your app upon creation.
Client Secret (Secret Key) 将这些凭证保密,如果秘密泄露,请立即轮换。
Redirect URIs 使用 HTTPS 回调 URL 进行生产集成。 Comma-separated list of authorized callback URLs where the authorization code will be sent.
2

配置 OAuth 2.0

实施授权代码流程,以允许成员安全地授予对其数据和身份的访问权限。

Step 1: Request Authorization Code

Redirect the user to the authorization endpoint. The user will be prompted to grant the requested permissions.

GET /oauth/authorize
GET https://testxxc.lockr.sbs/oauth/authorize?
    client_id=YOUR_CLIENT_ID&
    redirect_uri=https://yourapp.com/callback&
    response_type=code&
    scope=user.identity.read%20user.profile.read&
    state=RANDOM_CSRF_STATE

Step 2: Exchange Code for Access Token

Once authorized, the user is redirected back to your redirect_uri with a code query parameter. Exchange this code via a secure server-to-server POST request:

POST /oauth/token
POST https://testxxc.lockr.sbs/oauth/token
Content-Type: application/json

{
    "grant_type": "authorization_code",
    "client_id": "YOUR_CLIENT_ID",
    "client_secret": "YOUR_CLIENT_SECRET",
    "redirect_uri": "https://yourapp.com/callback",
    "code": "AUTHORIZATION_CODE"
}
JSON Response (HTTP 200)
{
    "access_token": "def50200a87...",
    "refresh_token": "def50200b92...",
    "expires_in": 3600,
    "token_type": "Bearer"
}

Step 3: Access Protected API Endpoints

Provide the access token in the Authorization: Bearer {access_token} HTTP header on all API requests:

GET /api/developer/v1/me
GET https://testxxc.lockr.sbs/api/developer/v1/me HTTP/1.1
Host: testxxc.lockr.sbs
Authorization: Bearer YOUR_ACCESS_TOKEN
Accept: application/json
3

代码示例

使用我们全面的代码示例连接您的后端或将交互式小部件直接嵌入到您的网站中。

PHP (cURL)
Node.js (Axios)
Python (Requests)
C# (.NET)
cURL CLI
PHP (cURL)
<?php
$clientId = 'YOUR_CLIENT_ID';
$clientSecret = 'YOUR_CLIENT_SECRET';
$code = $_GET['code']; // Code received from authorization redirect

// 1. Exchange code for access token
$ch = curl_init('https://testxxc.lockr.sbs/oauth/token');
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, [
    'grant_type'    => 'authorization_code',
    'client_id'     => $clientId,
    'client_secret' => $clientSecret,
    'redirect_uri'  => 'https://yourapp.com/callback',
    'code'          => $code
]);

$response = json_decode(curl_exec($ch), true);
$accessToken = $response['access_token'];

// 2. Fetch authenticated member identity
$ch = curl_init('https://testxxc.lockr.sbs/api/developer/v1/me');
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_HTTPHEADER, [
    'Authorization: Bearer ' . $accessToken,
    'Accept: application/json'
]);

$user = json_decode(curl_exec($ch), true);
print_r($user);
?>
Node.js (Axios)
const axios = require('axios');

async function authenticateAndFetchUser(authCode) {
    // 1. Exchange authorization code for token
    const tokenResponse = await axios.post('https://testxxc.lockr.sbs/oauth/token', {
        grant_type: 'authorization_code',
        client_id: 'YOUR_CLIENT_ID',
        client_secret: 'YOUR_CLIENT_SECRET',
        redirect_uri: 'https://yourapp.com/callback',
        code: authCode
    });

    const accessToken = tokenResponse.data.access_token;

    // 2. Call Developer API v1 endpoint
    const userResponse = await axios.get('https://testxxc.lockr.sbs/api/developer/v1/me', {
        headers: {
            'Authorization': `Bearer ${accessToken}`,
            'Accept': 'application/json'
        }
    });

    return userResponse.data.data;
}
Python (Requests)
import requests

def get_user_profile(auth_code):
    # 1. Exchange code for access token
    token_url = 'https://testxxc.lockr.sbs/oauth/token'
    payload = {
        'grant_type': 'authorization_code',
        'client_id': 'YOUR_CLIENT_ID',
        'client_secret': 'YOUR_CLIENT_SECRET',
        'redirect_uri': 'https://yourapp.com/callback',
        'code': auth_code
    }
    token_res = requests.post(token_url, data=payload)
    access_token = token_res.json().get('access_token')

    # 2. Call Developer API v1
    api_url = 'https://testxxc.lockr.sbs/api/developer/v1/me'
    headers = {
        'Authorization': f'Bearer {access_token}',
        'Accept': 'application/json'
    }
    user_res = requests.get(api_url, headers=headers)
    return user_res.json()
C# (HttpClient)
using System.Net.Http;
using System.Net.Http.Headers;
using System.Threading.Tasks;
using System.Collections.Generic;

public async Task<string> GetUserProfile(string authCode) {
    using var client = new HttpClient();

    // 1. Exchange code for token
    var parameters = new Dictionary<string, string> {
        { "grant_type", "authorization_code" },
        { "client_id", "YOUR_CLIENT_ID" },
        { "client_secret", "YOUR_CLIENT_SECRET" },
        { "redirect_uri", "https://yourapp.com/callback" },
        { "code", authCode }
    };

    var content = new FormUrlEncodedContent(parameters);
    var tokenResponse = await client.PostAsync("https://testxxc.lockr.sbs/oauth/token", content);
    var tokenJson = await tokenResponse.Content.ReadAsStringAsync();
    
    // Parse accessToken from tokenJson ...
    string accessToken = "EXTRACTED_ACCESS_TOKEN";

    // 2. Call Developer API v1
    client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken);
    client.DefaultRequestHeaders.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
    
    var userResponse = await client.GetAsync("https://testxxc.lockr.sbs/api/developer/v1/me");
    return await userResponse.Content.ReadAsStringAsync();
}
cURL CLI
# 1. Exchange authorization code for token
curl -X POST https://testxxc.lockr.sbs/oauth/token \
     -H "Content-Type: application/x-www-form-urlencoded" \
     -d "grant_type=authorization_code" \
     -d "client_id=YOUR_CLIENT_ID" \
     -d "client_secret=YOUR_CLIENT_SECRET" \
     -d "code=AUTHORIZATION_CODE" \
     -d "redirect_uri=https://yourapp.com/callback"

# 2. Call Developer API v1 with Bearer token
curl -X GET https://testxxc.lockr.sbs/api/developer/v1/me \
     -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
     -H "Accept: application/json"
4

API Endpoints Reference

Complete catalog of available REST API v1 endpoints with request parameters and required scopes. All requests require the Authorization: Bearer {token} header and are rate-limited to 30 requests per minute.

Identity & Profile

GET /api/developer/v1/me
user.identity.read

阅读会员帐户标识符和基本公共身份字段。

GET /api/developer/v1/me/profile
user.profile.read

阅读公共个人资料详细信息和核心成员元数据。

GET /api/developer/v1/me/email
user.email.read (Sensitive)

Access the primary verified email address of the member.

GET /api/developer/v1/me/social-links
user.social_links.read

阅读会员个人资料附带的公共社交链接。

GET /api/developer/v1/me/follows
user.follows.read

读取可见成员的关注者和关注关系。

POST /api/developer/v1/me/follows
user.follows.write (Sensitive)

Follow or unfollow other members on behalf of the user.

Payload: {"target_user_id": 123, "action": "follow|unfollow|toggle"}

Content & Interactions & Messages & Notifications

GET /api/developer/v1/me/content
user.content.read

Read public posts and status updates authored by the user.

POST /api/developer/v1/me/content
user.content.write (Sensitive)

Create, update, and publish posts on behalf of the user.

Payload: {"content": "Post text", "privacy": "public|followers|private"}
POST /api/developer/v1/me/reactions
user.reactions.write

Add or toggle likes and reactions to content on behalf of the user.

Payload: {"status_id": 123}
GET /api/developer/v1/me/messages
user.messages.read (Sensitive)

Read private direct message conversations belonging to the user.

POST /api/developer/v1/me/messages
user.messages.write (Sensitive)

Send private direct messages on behalf of the user.

Payload: {"receiver_id": 123, "content": "Message body"}
GET /api/developer/v1/me/notifications
user.notifications.read

Read account notifications, alerts, and unread counters.

Wallet & Rewards, Community & Media & Store & Advertising

GET /api/developer/v1/me/wallet
user.wallet.read (Sensitive)

Read user points balance, rewards, and wallet details.

GET /api/developer/v1/me/badges
user.badges.read

Read member badges, unlocked achievements, and quest status.

GET /api/developer/v1/me/clips
user.clips.read

Browse short video clips feed and saved clips in user account.

GET /api/developer/v1/forums
user.forums.read

Read forum categories, topics, discussions, and replies.

GET /api/developer/v1/store/products
user.store.read

Browse marketplace products, offerings, and store knowledgebase.

GET /api/developer/v1/me/orders
user.orders.read (Sensitive)

Read user purchase orders history and submitted offers.

GET /api/developer/v1/me/ads/stats
user.ads.read

Read ad impression counts, clicks, and campaign performance statistics.

App Owner Integrations

GET /api/developer/v1/owner/profile
owner.profile.read

通过开发者 API 读取授权所有者资料。

GET /api/developer/v1/owner/content
owner.content.read

阅读授权所有者内容源和发布的更新。

POST /api/developer/v1/owner/follow
owner.follow.write (Sensitive)

代表授权所有者关注或取消关注成员。

POST /api/developer/v1/owner/messages
owner.messages.write (Sensitive)

代表授权所有者发送私人消息。

Payload: {"content": "Message text"}
5

OAuth 2.0 Scopes Catalog

Granular permissions requested by third-party applications during the OAuth authorization flow.

Category Scope Identifier Description Type
Identity user.identity.read 阅读会员帐户标识符和基本公共身份字段。 Standard Scope
Identity user.profile.read 阅读公共个人资料详细信息和核心成员元数据。 Standard Scope
Identity user.email.read Access the primary verified email address of the member. Sensitive Scope
Identity user.social_links.read 阅读会员个人资料附带的公共社交链接。 Standard Scope
Identity user.follows.read 读取可见成员的关注者和关注关系。 Standard Scope
Identity user.follows.write Follow or unfollow other members on behalf of the user. Sensitive Scope
Content user.content.read Read public posts and status updates authored by the user. Standard Scope
Content user.content.write Create, update, and publish posts on behalf of the user. Sensitive Scope
Content user.reactions.write Add or toggle likes and reactions to content on behalf of the user. Standard Scope
Content user.comments.write Publish comments and replies on posts on behalf of the user. Sensitive Scope
Messaging user.messages.read Read private direct message conversations belonging to the user. Sensitive Scope
Messaging user.messages.write Send private direct messages on behalf of the user. Sensitive Scope
Messaging user.notifications.read Read account notifications, alerts, and unread counters. Standard Scope
Economy user.wallet.read Read user points balance, rewards, and wallet details. Sensitive Scope
Economy user.badges.read Read member badges, unlocked achievements, and quest status. Standard Scope
Community user.clips.read Browse short video clips feed and saved clips in user account. Standard Scope
Community user.clips.write Save and unsave short video clips on behalf of the user. Standard Scope
Community user.forums.read Read forum categories, topics, discussions, and replies. Standard Scope
Community user.forums.write Create new topics and post replies in forums on behalf of the user. Sensitive Scope
Commerce user.store.read Browse marketplace products, offerings, and store knowledgebase. Standard Scope
Commerce user.orders.read Read user purchase orders history and submitted offers. Sensitive Scope
Commerce user.ads.read Read ad impression counts, clicks, and campaign performance statistics. Standard Scope
Owner owner.profile.read 通过开发者 API 读取授权所有者资料。 Standard Scope
Owner owner.content.read 阅读授权所有者内容源和发布的更新。 Standard Scope
Owner owner.follow.write 代表授权所有者关注或取消关注成员。 Sensitive Scope
Owner owner.messages.read 阅读属于授权所有者的私人消息对话。 Sensitive Scope
Owner owner.messages.write 代表授权所有者发送私人消息。 Sensitive Scope
6

Embeddable JavaScript Widgets

在您的网站上嵌入我们的小部件以显示您的 MyAds 个人资料、内容或关注按钮。

1. Follow Button Widget

Embed an interactive button allowing visitors to follow your profile on MYADS with a single click.

HTML Embed Code
<div id="myads-widget-follow-YOUR_APP_ID"></div>
<script src="https://testxxc.lockr.sbs/embed/developer/YOUR_APP_ID/follow.js"></script>
2. Profile Card Widget

Display your verified badge, avatar, bio, follower count, and stats on your website.

HTML Embed Code
<div id="myads-widget-profile-YOUR_APP_ID"></div>
<script src="https://testxxc.lockr.sbs/embed/developer/YOUR_APP_ID/profile.js"></script>
3. Latest Content Feed Widget

Showcase your latest public posts and status updates dynamically inside your web application.

HTML Embed Code
<div id="myads-widget-content-YOUR_APP_ID"></div>
<script src="https://testxxc.lockr.sbs/embed/developer/YOUR_APP_ID/content.js"></script>
7

External Web Share API

使用共享 API 为帖子编辑器预先填充文本和链接。

GET /share Endpoint
https://testxxc.lockr.sbs/share?text=Check+out+this+article!+https://example.com
8

Rate Limiting & Security

API requests are limited to 30 requests per minute per client IP. Bearer tokens must be kept confidential.

Rate Limiting Standard Developer API endpoints: 30 requests per minute per client IP. Rate-limited requests receive HTTP 429 Too Many Requests.
Standard JSON Response Envelope Every response contains consistent success, message, and data fields:
{
    "success": true,
    "message": "Operation completed successfully.",
    "data": { ... }
}
Localization Support (Accept-Language) Send Accept-Language: ar or Accept-Language: en in request headers to receive localized responses and validation messages.
Continuous Audio Player
MYADS Audio
0:00
0:00