Skip to main content
Rookoo issues OAuth 2.0 access tokens as JWTs (RS256). Account administrators can register OAuth clients under Settings → Integrations → OAuth Applications. Super admins can also manage global clients (no account) in the super admin console. Account-scoped clients are tied to the account that created them. Only administrators of that account can list, update, or delete them.

Scopes

Create a client in the portal

  1. Open Settings → Integrations → OAuth Applications.
  2. Click New OAuth App.
  3. Set a name, redirect URI, and scopes.
  4. Copy the Client ID (uid) and Client Secret. The secret is shown in the app details and can be regenerated later.
Redirect URIs must use https, a custom scheme (for native apps), or http on localhost / 127.0.0.1. Public (non-confidential) clients must use PKCE.

Create a client via API

Requires an administrator user access token:
Response includes uid (client id) and secret. Regenerate the secret:

Authorization code flow

1. Send the user to authorize

The user must be signed in to the portal. After approval they are redirected with ?code=....

2. Exchange the code for tokens

Example response:
Access tokens expire after 2 hours. Use the refresh token to obtain a new access token without re-prompting the user.

3. Call the API

OAuth JWTs use the Authorization: Bearer header (not api_access_token). The token user must be a member of the account in the path.

Client credentials flow

For machine-to-machine clients that do not act as a user. Prefer authorization code when the integration needs user permissions.

Refresh tokens

Discovery endpoints

Manage clients via API

All of these routes require an administrator of {account_id}.