Skip to content
Bare BitcoinDevelopers

Search documentation

↑ ↓ Select · Enter Open · Escape Close

barebitcoin.no ↗
Menu
View Markdown

OAuth

OAuth provides access to supported operations on behalf of another user. Contact Bare Bitcoin to arrange client registration and your redirect URI. Registration is not self-service in these docs.

Authorization code flow

Direct the user to https://api.bb.no/oauth2/v0/authorize with response_type=code, your registered client_id, redirect_uri, requested scope, and an unpredictable state value. Validate the returned state before exchanging the authorization code. Use PKCE with an S256 challenge for public clients; keep the verifier for the token exchange.

Exchange the code by POSTing form-encoded parameters to https://api.bb.no/oauth2/v0/token: grant_type=authorization_code, code, client_id, redirect_uri, and the PKCE code_verifier when used. Confidential clients also send their registered client_secret in the form body. Never put a client secret in browser code.

Access and refresh tokens

Send the access token in the Authorization: Bearer header. Use the token response's expiry information; do not assume an access token remains valid indefinitely. Refresh using a form-encoded POST to the token endpoint with grant_type=refresh_token, refresh_token, and your client authentication. Persist replacement tokens returned by the server.

Scopes

Request only the scopes your integration needs.

ScopeGrantsEndpoints
api:accounts:bitcoin:readSee balance and names of your bitcoin accountsList bitcoin accounts, Tax balances
api:trades:readSee executed tradesNone
api:tax:transactions:readRead transactions relevant for tax calculationTax transactions
api:deposits:lightning:readSee Lightning invoices and their payment statusGet Lightning invoice
api:deposits:lightning:writeCreate Lightning invoices for payments to youCreate Lightning invoice

Revoke consent removes access for the specified application. It accepts an API key or any OAuth2 access token.