Menu
OAuth
OAuth provides access to supported operations on behalf of another user. Contact Bare Bitcoin to arrange client registration and your redirect URI. Registration is not self-service in these docs.
Authorization code flow
Direct the user to https://api.bb.no/oauth2/v0/authorize with
response_type=code, your registered client_id, redirect_uri, requested
scope, and an unpredictable state value. Validate the returned state before
exchanging the authorization code. Use PKCE with an S256 challenge for public
clients; keep the verifier for the token exchange.
Exchange the code by POSTing form-encoded parameters to
https://api.bb.no/oauth2/v0/token: grant_type=authorization_code, code,
client_id, redirect_uri, and the PKCE code_verifier when used.
Confidential clients also send their registered client_secret in the form
body. Never put a client secret in browser code.
Access and refresh tokens
Send the access token in the Authorization: Bearer header. Use the token
response's expiry information; do not assume an access token remains valid
indefinitely. Refresh using a form-encoded POST to the token endpoint with
grant_type=refresh_token, refresh_token, and your client authentication.
Persist replacement tokens returned by the server.
Scopes
Request only the scopes your integration needs.
| Scope | Grants | Endpoints |
|---|---|---|
api:accounts:bitcoin:read | See balance and names of your bitcoin accounts | List bitcoin accounts, Tax balances |
api:trades:read | See executed trades | None |
api:tax:transactions:read | Read transactions relevant for tax calculation | Tax transactions |
api:deposits:lightning:read | See Lightning invoices and their payment status | Get Lightning invoice |
api:deposits:lightning:write | Create Lightning invoices for payments to you | Create Lightning invoice |
Revoking consent
Revoke consent removes access for the specified application. It accepts an API key or any OAuth2 access token.