Developer
Authorization flow
Authorization code grant, step by step, with the exact requests.
1 · Redirect the user
text
https://dashboard.trabalance.com/oauth/authorize
?client_id=tc_…
&redirect_uri=https://your-app.example/callback
&response_type=code
&state=<random, stored in the user's session>A signed-out visitor is sent to sign in first, carrying this whole request as the return path, and lands back on the consent screen.
The consent screen lists the scopes your app may receive; the user can untick any. Whatever they allow is still bounded to their own rights.
2 · Receive the code
The user returns to redirect_uri?code=…&state=… (or ?error=access_denied&state=… if they cancel). Check state matches what you stored. Codes live 10 minutes and are single-use.
3 · Exchange it
bash
curl -X POST https://api.trabalance.com/oauth/token \
-H "Content-Type: application/json" \
-d '{ "grant_type": "authorization_code", "code": "…",
"redirect_uri": "https://your-app.example/callback",
"client_id": "tc_…", "client_secret": "…" }'json
{ "access_token": "…", "token_type": "Bearer", "expires_in": 3600,
"refresh_token": "…", "scope": "sales_customers:read sales_invoices:read sales_invoices:create" }4 · Refresh
bash
curl -X POST https://api.trabalance.com/oauth/token \
-H "Content-Type: application/json" \
-d '{ "grant_type": "refresh_token", "refresh_token": "…", "client_id": "tc_…", "client_secret": "…" }'Both tokens rotate. Refresh tokens live 90 days.
5 · Revoke
POST /oauth/revoke with { "token": "…" } (either kind). The user can also revoke from their side at any time.
| Grant | Supported |
|---|---|
| authorization_code | Yes |
| refresh_token | Yes |
| client_credentials | No — use an API key for machine-to-machine. |
| PKCE | Not yet supported. |
ℹ️Scope strings
Scopes are feature_code:verb, e.g. sales_invoices:create. See Permission scopes.