놀아 Account
Contents

Changelog

Changes to the 놀아 Account OAuth platform, in order.

This is the change history for the brand assets and the API, newest first. Changes that affect your integration are shown in bold.

2026-10-02

Multilingual — English and Vietnamese

  • ui_locales added — add it to the authorization request and the sign-in and consent screens appear in that language. ko, en and vi are supported. The integration guide shows how to use it.
  • Sign-in and consent screens, and the notification emails, now go out in the user's language. Users can also switch language themselves from the top of the screen.
  • These developer docs are available in English and Vietnamese too.
Existing integrations keep working. ui_locales is optional, and nothing changed in the endpoints, scopes or token specification. ui_locales affects the screen language only and has no bearing on authentication or permissions.

2026-09-03

Full brand overhaul

  • New mark — The mark is replaced with a new one that has a brush-drawn L-shaped stroke (the Hangul consonant for “n”) and a vermilion seal. Download it from the Brand guide.
  • Service name change — “놀아:Member” → “놀아 Account”. The sign-in button text is unified as “놀아로 계속하기” (“Continue with Nolaa” in English).
  • Brand color change — Blue #0066FF → vermilion #D6342C, ink #15120F.
  • Favicon, app icon and share card images all replaced.
Services that use the old button keep working even if you don't change it right away. There are no changes to the API, endpoints or scopes. We would still like you to move to the new mark and text at your next release.

New developer docs

Clarified in the docs (no behavior change)

The items below already worked this way but were not properly written down in the docs. There are no code changes.

  • PKCE is required. A request without code_challenge is rejected with pkce_required, and only S256 is accepted.
  • state is required too. If it is missing, you get invalid_request.
  • Email is provided by default (opt-out). It is folded into profile.basic, and can be turned off per service. The detailed conditions are in the Scope reference.
  • A new refresh_token is issued on every refresh and the old one is revoked (refresh token rotation). You must store the new value from the response.
  • There is no public endpoint for disconnecting (revoke). Treat 401 invalid_token as your sign-out signal.