Scopes
Create a client in the portal
- Open Settings → Integrations → OAuth Applications.
- Click New OAuth App.
- Set a name, redirect URI, and scopes.
- Copy the Client ID (
uid) and Client Secret. The secret is shown in the app details and can be regenerated later.
https, a custom scheme (for native apps), or http on localhost / 127.0.0.1. Public (non-confidential) clients must use PKCE.
Create a client via API
Requires an administrator user access token:uid (client id) and secret.
Regenerate the secret:
Authorization code flow
1. Send the user to authorize
?code=....
2. Exchange the code for tokens
3. Call the API
Authorization: Bearer header (not api_access_token). The token user must be a member of the account in the path.
Client credentials flow
For machine-to-machine clients that do not act as a user. Prefer authorization code when the integration needs user permissions.Refresh tokens
Discovery endpoints
Manage clients via API
All of these routes require an administrator of
{account_id}.