# OAuth

OAuth provides access to supported operations on behalf of another user. Contact
Bare Bitcoin to arrange client registration and your redirect URI. Registration
is not self-service in these docs.

## Authorization code flow

Direct the user to `https://api.bb.no/oauth2/v0/authorize` with
`response_type=code`, your registered `client_id`, `redirect_uri`, requested
`scope`, and an unpredictable `state` value. Validate the returned state before
exchanging the authorization code. Use PKCE with an S256 challenge for public
clients; keep the verifier for the token exchange.

Exchange the code by POSTing form-encoded parameters to
`https://api.bb.no/oauth2/v0/token`: `grant_type=authorization_code`, `code`,
`client_id`, `redirect_uri`, and the PKCE `code_verifier` when used.
Confidential clients also send their registered `client_secret` in the form
body. Never put a client secret in browser code.

## Access and refresh tokens

Send the access token in the `Authorization: Bearer` header. Use the token
response's expiry information; do not assume an access token remains valid
indefinitely. Refresh using a form-encoded POST to the token endpoint with
`grant_type=refresh_token`, `refresh_token`, and your client authentication.
Persist replacement tokens returned by the server.

## Scopes

Request only the scopes your integration needs.

| Scope | Grants | Endpoints |
| --- | --- | --- |
| `api:accounts:bitcoin:read` | See balance and names of your bitcoin accounts | [List bitcoin accounts](https://barebitcoin.no/developers/api/accounts/bitcoin-accounts), [Tax balances](https://barebitcoin.no/developers/api/tax/balances) |
| `api:trades:read` | See executed trades | None |
| `api:tax:transactions:read` | Read transactions relevant for tax calculation | [Tax transactions](https://barebitcoin.no/developers/api/tax/transactions) |
| `api:deposits:lightning:read` | See Lightning invoices and their payment status | [Get Lightning invoice](https://barebitcoin.no/developers/api/transfers/get-lightning-invoice) |
| `api:deposits:lightning:write` | Create Lightning invoices for payments to you | [Create Lightning invoice](https://barebitcoin.no/developers/api/transfers/create-lightning-invoice) |

## Revoking consent

[Revoke consent](https://barebitcoin.no/developers/api/accounts/revoke-consent) removes access for the
specified application. It accepts an API key or any OAuth2 access token.


Source: https://barebitcoin.no/developers/authentication/oauth
