FlashlineFlashlineDevelopers
DocsDashboard
Guides
Getting startedConnect accountsVersioningErrors
Reference
AuthenticationGET /oauth/authorizePOST /oauth/tokenPOST /oauth/revoke
Account
GET /me
Measurements
POST /measurementsGET /measurements/{id}
Reference

Authentication

/api/oauth/authorize runs in the browser. /api/oauth/token and /api/oauth/revoke are server-to-server form requests; responses are JSON.

GET/oauth/authorize

A browser page. Send the contractor here to approve the connection. Signed-out contractors sign in first, then continue.

QueryDescription
client_idrequiredYour app's client ID.
redirect_urirequiredMust exactly match a redirect URI listed in the dashboard. Registered URIs are https, except http://localhost and http://127.0.0.1 (any port), accepted for local testing.
response_typerequiredAlways code.
staterequiredRandom value, returned to you unchanged.
code_challengerequiredPKCE challenge: base64url of the SHA-256 of your code_verifier, 43 characters.
code_challenge_methodrequiredAlways S256.
Redirect on Allow
https://app.example.com/flashline/callback
?code=cn_9KdT3…
&state=8f2c1d…

# On Deny
https://app.example.com/flashline/callback
?error=access_denied
&state=8f2c1d…
POST/oauth/token

Exchanges a code for an access token. Client credentials go in the form body. Exchanging replaces the connection's previous token, so one is live per connected team.

Form fieldDescription
grant_typerequiredAlways authorization_code.
coderequiredFrom the redirect. Single use, valid 10 minutes.
redirect_urirequiredThe same value you sent to authorize.
client_idrequiredYour app's client ID.
client_secretrequiredYour app's client secret.
code_verifierrequiredThe PKCE verifier your code_challenge was derived from, 43 to 128 characters.

invalid_grant for a used, expired or mismatched code, or a wrong code_verifier (the code is consumed either way); invalid_client for bad credentials.

Response 200
{
"access_token": "flt_Zt8m…",
"token_type": "bearer",
"team": { "id": "7c1e5a0e-…", "name": "Acme Gutters" },
"connected_at": "2026-09-02T13:58:02Z"
}

// 400 Bad Request
{ "error": "invalid_grant" }
POST/oauth/revoke

Revokes an access token.

Form fieldDescription
tokenrequiredThe access token to revoke.
client_idrequiredYour app's client ID.
client_secretrequiredYour app's client secret.
Response
# 200 OK, empty body
Terms•Privacy