Developer

Authorization flow

Authorization code grant, step by step, with the exact requests.

1 · Redirect the user

text
https://dashboard.trabalance.com/oauth/authorize
?client_id=tc_…
&redirect_uri=https://your-app.example/callback
&response_type=code
&state=<random, stored in the user's session>

A signed-out visitor is sent to sign in first, carrying this whole request as the return path, and lands back on the consent screen.

The consent screen. Every scope starts ticked; whatever survives is intersected with the user's own rights before a code is issued.

The consent screen lists the scopes your app may receive; the user can untick any. Whatever they allow is still bounded to their own rights.

2 · Receive the code

The user returns to redirect_uri?code=…&state=… (or ?error=access_denied&state=… if they cancel). Check state matches what you stored. Codes live 10 minutes and are single-use.

3 · Exchange it

bash
curl -X POST https://api.trabalance.com/oauth/token \
-H "Content-Type: application/json" \
-d '{ "grant_type": "authorization_code", "code": "…",
      "redirect_uri": "https://your-app.example/callback",
      "client_id": "tc_…", "client_secret": "…" }'
json
{ "access_token": "…", "token_type": "Bearer", "expires_in": 3600,
"refresh_token": "…", "scope": "sales_customers:read sales_invoices:read sales_invoices:create" }

4 · Refresh

bash
curl -X POST https://api.trabalance.com/oauth/token \
-H "Content-Type: application/json" \
-d '{ "grant_type": "refresh_token", "refresh_token": "…", "client_id": "tc_…", "client_secret": "…" }'

Both tokens rotate. Refresh tokens live 90 days.

5 · Revoke

POST /oauth/revoke with { "token": "…" } (either kind). The user can also revoke from their side at any time.

GrantSupported
authorization_codeYes
refresh_tokenYes
client_credentialsNo — use an API key for machine-to-machine.
PKCENot yet supported.
ℹ️Scope strings

Scopes are feature_code:verb, e.g. sales_invoices:create. See Permission scopes.