Reference
Authentication
/api/oauth/authorize runs in the browser. /api/oauth/token and /api/oauth/revoke are server-to-server form requests; responses are JSON.
A browser page. Send the contractor here to approve the connection. Signed-out contractors sign in first, then continue.
| Query | Description |
|---|---|
| client_idrequired | Your app's client ID. |
| redirect_urirequired | Must exactly match a redirect URI listed in the dashboard. Registered URIs are https, except http://localhost and http://127.0.0.1 (any port), accepted for local testing. |
| response_typerequired | Always code. |
| staterequired | Random value, returned to you unchanged. |
| code_challengerequired | PKCE challenge: base64url of the SHA-256 of your code_verifier, 43 characters. |
| code_challenge_methodrequired | Always S256. |
Redirect on Allow
https://app.example.com/flashline/callback
?code=cn_9KdT3…
&state=8f2c1d…
# On Deny
https://app.example.com/flashline/callback
?error=access_denied
&state=8f2c1d…
POST/oauth/token
Exchanges a code for an access token. Client credentials go in the form body. Exchanging replaces the connection's previous token, so one is live per connected team.
| Form field | Description |
|---|---|
| grant_typerequired | Always authorization_code. |
| coderequired | From the redirect. Single use, valid 10 minutes. |
| redirect_urirequired | The same value you sent to authorize. |
| client_idrequired | Your app's client ID. |
| client_secretrequired | Your app's client secret. |
| code_verifierrequired | The PKCE verifier your code_challenge was derived from, 43 to 128 characters. |
invalid_grant for a used, expired or mismatched code, or a wrong code_verifier (the code is consumed either way); invalid_client for bad credentials.
Response 200
{
"access_token": "flt_Zt8m…",
"token_type": "bearer",
"team": { "id": "7c1e5a0e-…", "name": "Acme Gutters" },
"connected_at": "2026-09-02T13:58:02Z"
}
// 400 Bad Request
{ "error": "invalid_grant" }
POST/oauth/revoke
Revokes an access token.
| Form field | Description |
|---|---|
| tokenrequired | The access token to revoke. |
| client_idrequired | Your app's client ID. |
| client_secretrequired | Your app's client secret. |
Response
# 200 OK, empty body