You're writing a server-side client for anyone to use, not just yourself? Then the server should make the call. It'll redirect the user's browser to an authorization page, which will then forward back to your app.