FlashlineFlashlineDevelopers
DocsDashboard
Guides
Getting startedConnect accountsVersioningErrors
Reference
AuthenticationGET /oauth/authorizePOST /oauth/tokenPOST /oauth/revoke
Account
GET /me
Measurements
POST /measurementsGET /measurements/{id}

Connect accounts

OAuth 2.0 authorization code with PKCE (S256). Access tokens do not expire and there are no refresh tokens.

client_id · client_secret
Client credentials

One pair per app, from the developer dashboard. Keep the secret on your server.

access_token
Access token

One per connected team, from the token endpoint. Send it as the bearer on every API call. Reconnecting replaces it.

The Connect flow

  1. 1

    Send the contractor to the authorize URL with your client_id, redirect_uri, a random state and a PKCE code_challenge (S256). Open it top-level or in a popup; it cannot be framed.

  2. 2

    They sign in to Flashline and click Allow. Any member of the team can; the connection belongs to the team.

  3. 3

    Flashline redirects to your redirect_uri with a code and your state.

  4. 4

    Exchange the code at the token endpoint, with the code_verifier, for an access_token.

Tokens do not expire. Codes are single use and last 10 minutes.

PKCE is required. Send a code_challenge (S256) to authorize and the matching code_verifier to the token endpoint. Most OAuth libraries handle this for you.

Reconnecting issues a new token and invalidates the previous one. One token is live per connected team.

Disconnect from either side. Contractors can disconnect in Flashline; you can call POST /api/oauth/revoke.

One base URL. There is no sandbox host: a development app and a production app both talk to www.flashlinegutters.com, and each creates real requests in whichever team connects it. Create one app per environment, and connect the development one to your organization's test account, the contractor team Flashline created for you.

Rate limit. 600 requests per hour per connected team. Errors covers 429 and when to retry.

Step 1: send the contractor to authorize
https://www.flashlinegutters.com/api/oauth/authorize
?client_id=flc_9Hx2Kd
&redirect_uri=https://app.example.com/flashline/callback
&response_type=code
&state=8f2c1d…
&code_challenge=E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM
&code_challenge_method=S256
Step 3: Flashline redirects back
https://app.example.com/flashline/callback
?code=cn_9KdT3…
&state=8f2c1d…
Step 4: exchange the code
curl -X POST https://www.flashlinegutters.com/api/oauth/token \
-d grant_type=authorization_code \
-d code=cn_9KdT3… \
-d redirect_uri=https://app.example.com/flashline/callback \
-d client_id=flc_9Hx2Kd \
-d client_secret=fls_… \
-d code_verifier=dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk
Token response
{
"access_token": "flt_Zt8m…",
"token_type": "bearer",
"team": { "id": "7c1e5a0e-…", "name": "Acme Gutters" },
"connected_at": "2026-09-02T13:58:02Z"
}
Terms•Privacy