Connect accounts
OAuth 2.0 authorization code with PKCE (S256). Access tokens do not expire and there are no refresh tokens.
One pair per app, from the developer dashboard. Keep the secret on your server.
One per connected team, from the token endpoint. Send it as the bearer on every API call. Reconnecting replaces it.
The Connect flow
- 1
Send the contractor to the authorize URL with your
client_id,redirect_uri, a randomstateand a PKCEcode_challenge(S256). Open it top-level or in a popup; it cannot be framed. - 2
They sign in to Flashline and click Allow. Any member of the team can; the connection belongs to the team.
- 3
Flashline redirects to your
redirect_uriwith acodeand yourstate. - 4
Exchange the code at the token endpoint, with the
code_verifier, for anaccess_token.
Tokens do not expire. Codes are single use and last 10 minutes.
PKCE is required. Send a code_challenge (S256) to authorize and the matching code_verifier to the token endpoint. Most OAuth libraries handle this for you.
Reconnecting issues a new token and invalidates the previous one. One token is live per connected team.
Disconnect from either side. Contractors can disconnect in Flashline; you can call POST /api/oauth/revoke.
One base URL. There is no sandbox host: a development app and a production app both talk to www.flashlinegutters.com, and each creates real requests in whichever team connects it. Create one app per environment, and connect the development one to your organization's test account, the contractor team Flashline created for you.
Rate limit. 600 requests per hour per connected team. Errors covers 429 and when to retry.
https://www.flashlinegutters.com/api/oauth/authorize
?client_id=flc_9Hx2Kd
&redirect_uri=https://app.example.com/flashline/callback
&response_type=code
&state=8f2c1d…
&code_challenge=E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM
&code_challenge_method=S256
https://app.example.com/flashline/callback
?code=cn_9KdT3…
&state=8f2c1d…
curl -X POST https://www.flashlinegutters.com/api/oauth/token \
-d grant_type=authorization_code \
-d code=cn_9KdT3… \
-d redirect_uri=https://app.example.com/flashline/callback \
-d client_id=flc_9Hx2Kd \
-d client_secret=fls_… \
-d code_verifier=dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk
{
"access_token": "flt_Zt8m…",
"token_type": "bearer",
"team": { "id": "7c1e5a0e-…", "name": "Acme Gutters" },
"connected_at": "2026-09-02T13:58:02Z"
}