To register your application in Yandex.Money, follow these steps:
- Log in to your Yandex.Money wallet with your username. If you don't have a wallet, create it.
- Go to the App registration page.
- Set the application parameters:
- The name of your application (for example, “Mobile store”).
- Your application's logo.
- Link to the application's or the developer’s website.
URI for returning the result of application authorization (see redirect_uri in the OAuth 2.0 Authorization Protocol).
- Use application authenticity verification
- Specify whether you want to use the secret word for verifying the authenticity of the application (see the description of client_secret in The OAuth 2.0 Authorization Framework).
- Click the Confirm button.
The App data page opens, where you will see the name of your application, its ID (client_id), and, if the corresponding option is selected, the secret word that was generated (client_secret).CAUTION.
The application developer should never openly publish the application's client_id anywhere. Leaking the client_id might provoke "phishing attacks," where applications or sites are launched to get access tokens in your name. If this happens, Yandex.Money will assume that it is receiving requests from your application.
To prevent this, you can use the secret word (client_secret) known only to the app developer. The application developer should ensure that the secret word (client_secret) is kept confidential.