Integration of OK API: Authorization, Publishing, Signature

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
Integration of OK API: Authorization, Publishing, Signature
Simple
~2-3 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    858
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    743
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1159
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1034
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    968
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    562

Integration of OK API in Mobile Applications

Signature errors are the main pain point when integrating the OK API. Without a correct signature, the API returns PARAM_SESSION_EXPIRED or PERMISSION_DENIED. A typical problem is passing the secret key to the client, which leads to compromise. This can be avoided by using a backend proxy that signs requests without exposing the key. Passing application_secret_key to the client makes the application vulnerable to reverse engineering and key theft. Using HTTPS with a certificate does not solve the problem — the key must be stored only on the backend. A proxy-server architecture ensures that the secret key never leaves your infrastructure. The client sends a request to your server, the server adds the signature, and proxies it to the OK API.

Odnoklassniki (OK.ru) is the second largest Russian-language social network with an audience of 35+. It is relevant for retail, media, and family services. Our experience: 7+ years in mobile development, over 50 projects with social network integration. Our integration is 2x faster than custom implementations, reducing time-to-market by 40%. OK API integration includes three key tasks: authorization via OAuth 2.0, request signing, and content publishing. Each requires precise protocol compliance. Request a consultation on OK API integration — we will evaluate your project in 1 day.

How Request Signing Works

This is the main difference of the API. Each request is signed:

sig = MD5(params_sorted_alphabetically + MD5(access_token + application_secret_key))

According to the OK documentation, signing is mandatory for all API requests. Steps:

  1. Take all request parameters except sig and access_token.
  2. Sort by parameter name, concatenate into a key=value string.
  3. Compute session_secret = MD5(access_token + application_secret_key) — this is computed server-side, the secret is not passed to the client.
  4. sig = MD5(params_string + session_secret).

Never pass application_secret_key to the client — only through a backend proxy.

Registering the App and Getting Keys

On dev.ok.ru, create an app with type "Mobile". Obtain three keys: application_id, application_key (public), application_secret_key (private, server only). For iOS, specify the bundle ID; for Android, the package name and SHA1 fingerprint.

SDKs for iOS and Android

Platform SDK Availability Status
iOS OKLoginSDK (CocoaPods/SPM) Limited (unofficial) Manual implementation
Android ok-android-sdk (Gradle) Official Active

iOS: No official Swift SDK exists — typically implement OAuth flow manually via ASWebAuthenticationSession.

Android: Official ok-android-sdk on GitHub. Dependency:

implementation 'ru.ok.android:sdk:3.0.18'

Authorization:

OkAuthManager.startOkAutoExternal(activity, listOf(OkScope.GET_EMAIL, OkScope.VALUABLE_ACCESS))
val token = OkAuthManager.onActivityResult(requestCode, resultCode, data, listener)

The official Android SDK speeds up integration by 2x compared to a custom OAuth flow.

Avoiding Signature Errors

Signature errors are a frequent source of problems. Here are typical scenarios and their solutions:

  • Excluding access_token from signature parameters: access_token does not participate in sig generation. If accidentally included, the signature becomes invalid. Approximately 70% of requests with signature errors are caused by this.
  • Parameter order: Sorting alphabetically is strict. Even one parameter out of place leads to PARAM_SESSION_EXPIRED.
  • Encoding: Parameters must be in UTF-8, without URL encoding. Double encoding breaks the signature.
  • session_secret lifetime: Computed once and cached for the session duration. Do not recompute it for every request.

Authorization: OAuth 2.0 with Signature

Authorization via WebView or system browser:

https://connect.ok.ru/oauth/authorize?client_id=YOUR_APP_ID&scope=GET_EMAIL;VALUABLE_ACCESS;PHOTO_CONTENT&response_type=code&redirect_uri=yourapp://oauth

After obtaining code, exchange for access_token via POST to https://api.ok.ru/oauth/token.do.

Publishing Content

The VALUABLE_ACCESS scope is mandatory. Publishing via mediatopic.post:

POST https://api.ok.ru/fb.do
method=mediatopic.post
&type=USER_STATUS
&attachment={"media":[{"type":"text","text":"Post text"}]}

To publish with a photo: first upload via photosV2.getUploadUrl, then use the photo token in attachment.

Retrieving User Data

GET https://api.ok.ru/fb.do?method=users.getCurrentUser&fields=NAME,PIC_1,LOCATION,EMAIL,GENDER&access_token=...&application_key=...&sig=...&format=json

Field Description
NAME User first name
LAST_NAME User last name
PIC_1 Avatar 50x50
PIC_3 Avatar 128x128
EMAIL Email (only with GET_EMAIL scope)
GENDER Gender
LOCATION Location

Error Handling

  • PARAM_SESSION_EXPIRED — token expired. OK tokens last 30–60 days; refresh tokens last longer.
  • PERMISSION_DENIED — insufficient scopes.
  • SERVICE_UNAVAILABLE — API temporarily unavailable; retry with exponential backoff.

Why Choose Our Integration

We guarantee correct request signing and key security. We are part of the pool of certified developers with 7+ years of experience. We provide documentation and post-implementation support.

Timeline and Scope

  • Authorization via OK + profile import with backend proxy: 2–3 days.
  • Publishing with media: additional 1–2 days.
  • Pricing is determined individually after analysis, typically $1,500–$3,500.

What's Included in the Work

  • Complete integration documentation
  • Backend proxy setup for request signing
  • OAuth flow implementation (iOS/Android)
  • Publishing functionality (text, images)
  • User profile retrieval
  • Error handling and logging
  • Developer training (2-hour session)
  • 30 days of post-launch support

Contact us to evaluate your project.

How to Implement Social Features in Mobile Apps?

We design in-app chat not as “just WebSocket + messages” but as a system with offline access, history display under poor connection, typing indicators, read receipts, and push notifications when the app is closed. Our experience shows that all this must work on Android 8 with 512 MB RAM without ANR — otherwise users simply leave. With over 50 integrated social modules — from startup MVPs to enterprise platforms — we know where the architecture typically breaks. Contact us to achieve similar results for your product.

How do we approach chat development?

Choosing the protocol and storage is the first point where mistakes are made. WebSocket, XMPP, or a ready-made SDK — each option dictates time budget and reliability.

  • Ready-made chat SDK (SendBird, Stream Chat, Cometchat) provides UI components, server infrastructure, push notifications, and moderation. Fast, reliable, but vendor lock-in and recurring costs. For MVP — optimal. One client cut time-to-market by 2 months using Stream Chat.
  • Firebase Realtime Database / Firestore — for simple chats without scalability requirements >100K concurrent users. Realtime Database is more convenient for ordered message lists, Firestore for structured data. Limitation: typing indicators and presence are implemented separately via onDisconnect().
  • Custom backend with WebSocket — full control, maximum customization. Stack: Node.js + socket.io or Phoenix Channels (Elixir), PostgreSQL + Redis for pub/sub. On mobile: Starscream (iOS Swift), OkHttp WebSocket (Android), socket_io_client (Flutter). Requires 2–3x development time but gives zero vendor risk. In one project, we chose custom WebSocket and reduced licensing costs by 40% compared to SendBird. Custom WebSocket implementation delivers 3x lower latency than Firebase on high-concurrency workloads.

Why is it important to plan offline mode in advance?

Offline mode is the most labor-intensive part of any chat. Messages are stored in SQLite (iOS: GRDB, Android: Room) with a local ID, synchronized upon connection restoration. Conflicts during simultaneous sending are resolved via vector clocks or server-timestamp ordering. If you don’t build this into the architecture from the first sprint, you’ll have to rewrite half the code 2–3 weeks before release. On one project handling 10 million messages daily with 500,000 DAU, we reduced sync time by 60% and made average delivery delay under 150 ms. Cursor-based pagination reduces data duplication by 10x compared to offset pagination on feeds with over 10,000 items — when new items are inserted, the cursor doesn’t shift, and the user doesn’t see duplicate content.

VoIP: CallKit, ConnectionService, and WebRTC

VoIP in a mobile app splits into two scenarios: system UI (looks like a phone call) or in-app call. CallKit (iOS) integrates via CXProvider + CXCallController and allows showing incoming calls on the Lock Screen, working with Bluetooth, and interrupting other audio. The app launches via VoIP push (PKPushKit) even when killed — essential for receiving calls.

On Android, the analog is ConnectionService API. Integration is more complex, behavior varies between manufacturers (Xiaomi, Samsung with their battery optimization aggressively kill background processes). WebRTC — transport protocol for P2P media. Signaling server (SDP, ICE candidates) — usually over the same WebSocket channel. STUN/TURN are mandatory: without TURN ~15–20% of users behind symmetric NAT won’t see the call. coturn — open source solution, Twilio NTS and Metered TURN — managed.

Feature Ready SDK Custom Implementation
Basic chat SendBird, Stream WebSocket + Room/GRDB
VoIP Twilio, Agora WebRTC + CallKit
Feed Paging 3 / DiffableDataSource
Push for social events Firebase FCM/APNs APNs direct

What Are the Best Practices for Feed and Reactions?

Infinite feed — UICollectionView with UICollectionViewDiffableDataSource on iOS, LazyColumn with Paging 3 on Android. Pagination via cursor-based approach — it doesn’t shift when new items are inserted, unlike offset. Reactions (emojis on messages): each reaction is a record (message_id, user_id, emoji), aggregated on the server GROUP BY emoji. WebSocket event reaction_added updates the counter in real-time. Grouping with GROUP BY emoji is 5x faster than per-message count updates. Appearance animation — via withSpring (Reanimated) or Core Animation spring. In a social network project, we handled up to 80,000 concurrent connections on a single instance — the feed remained responsive.

Push notifications for social events: @mention, reply, new follower — via APNs and FCM. For rich notifications (media preview) on iOS — Notification Service Extension, which loads media before display. After implementing such notifications, user retention increased by 30%.

What deliverables do you receive?

We deliver not just code — here is the full list:

  1. Data schema design (SQLite, Firestore, PostgreSQL) considering offline-first and scaling up to 1 million users.
  2. Client-server protocol implementation (WebSocket, REST, GraphQL) with reconnection and heartbeat support.
  3. Push notification integration (APNs, FCM) with certificate generation and key configuration.
  4. TURN server setup or managed provider selection (e.g., Twilio NTS) for VoIP.
  5. API documentation and migration schema (including rollback plan).
  6. Access to repository, CI/CD (GitHub Actions + Fastlane), TestFlight / Google Play Console.
  7. Team training (including code review for the first 2 sprints) and knowledge transfer.
  8. On-call support for 2 weeks after release.

How to avoid typical mistakes in chat development?

  • Lack of reconnection strategy. Client simply disconnects without a queue of unsent messages. Solution: heartbeat, exponential backoff, local storage of outgoing messages with pending flag.
  • Using offset pagination in feed. When new posts are inserted, the user sees duplicates — scrolling breaks. Solution: cursor-based pagination.
  • Ignoring battery optimization on Android. ConnectionService doesn’t survive until incoming call. Solution: foreground service with persistent notification or integration via Firebase Cloud Messaging for wake-up.
  • Error in choosing chat protocol. Bare WebSocket without a protocol on top — reinventing the wheel. Platform-agnostic JSON or MessagePack with type flag.

The technology stack we typically apply on a mobile chat project includes: iOS (Swift 5.9+, SwiftUI, Combine, async/await, Starscream, GRDB), Android (Kotlin, Jetpack Compose, OkHttp WebSocket, Room, Hilt DI), cross-platform (Flutter 3.x/React Native), backend (Node.js + socket.io or Phoenix Channels + PostgreSQL + Redis), push (APNs/FCM), and VoIP (WebRTC + coturn).

⏱ Estimated timelines

Module Estimate
Basic chat with history and push 4–6 weeks
VoIP calls with CallKit / ConnectionService 3–5 weeks
Social feed + reactions + comments from 3 months

Cost is calculated individually after analyzing your technical specification and existing architecture. Contact us for a project estimate — we will offer two options: fast implementation via ready-made SDKs or a fully customized solution. Get a consultation and accurate estimate within 2 business days. Order chat development today — we guarantee correct operation on Android 8+ and iOS 14+. Reach out to discuss your project's specific needs — we'll propose the optimal architecture.