curl --request POST \
--url http://localhost:3500/v1/integrations/authorizations/complete \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"state": "<string>",
"code": "<string>",
"browser_nonce": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({state: '<string>', code: '<string>', browser_nonce: '<string>'})
};
fetch('http://localhost:3500/v1/integrations/authorizations/complete', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "http://localhost:3500/v1/integrations/authorizations/complete"
payload = {
"state": "<string>",
"code": "<string>",
"browser_nonce": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"provider": "<string>",
"name": "<string>",
"status": "connected",
"syncable": true,
"enabled": true,
"auto_sync": true,
"scope": {
"suppliers": {
"mode": "all",
"items": [
{
"id": "<string>",
"name": "<string>",
"code": "<string>",
"group": {
"kind": "vendor-sites",
"prefixes": [
"<string>"
],
"site_count": 123,
"inactive_site_count": 1
}
}
],
"include_unidentified": true
},
"companies": [
{
"id": "<string>",
"name": "<string>",
"country_code": "<string>",
"accounting_currency_code": "<string>"
}
],
"processing_statuses": [
"<string>"
],
"path_globs": [
"<string>"
],
"module_company_codes": {
"costinvoice": [
"<string>"
],
"purchaseorder": [
"<string>"
]
}
},
"credentials": {
"values": {},
"secrets_set": [
"<string>"
]
},
"realtime": {
"supported": true,
"status": "active"
},
"rate_limited_until": "2023-11-07T05:31:56Z",
"last_successful_sync": {
"started_at": "2023-11-07T05:31:56Z",
"trigger": "manual"
},
"active_sync_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"provider": "<string>",
"name": "<string>",
"status": "connected",
"syncable": true,
"enabled": true,
"auto_sync": true,
"scope": {
"suppliers": {
"mode": "all",
"items": [
{
"id": "<string>",
"name": "<string>",
"code": "<string>",
"group": {
"kind": "vendor-sites",
"prefixes": [
"<string>"
],
"site_count": 123,
"inactive_site_count": 1
}
}
],
"include_unidentified": true
},
"companies": [
{
"id": "<string>",
"name": "<string>",
"country_code": "<string>",
"accounting_currency_code": "<string>"
}
],
"processing_statuses": [
"<string>"
],
"path_globs": [
"<string>"
],
"module_company_codes": {
"costinvoice": [
"<string>"
],
"purchaseorder": [
"<string>"
]
}
},
"credentials": {
"values": {},
"secrets_set": [
"<string>"
]
},
"realtime": {
"supported": true,
"status": "active"
},
"rate_limited_until": "2023-11-07T05:31:56Z",
"last_successful_sync": {
"started_at": "2023-11-07T05:31:56Z",
"trigger": "manual"
},
"active_sync_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "validation_error",
"message": "Invalid request format, parameters, or body. Details contain up to 20 actionable field errors; the complete encoded request body must be at most 2 MiB (2,097,152 bytes).",
"request_id": "req_example"
}
}{
"error": {
"code": "invalid_token",
"message": "Missing or invalid bearer credential.",
"request_id": "req_example"
}
}{
"error": {
"code": "forbidden",
"message": "Access denied: forbidden, token_disabled, organization_required, insufficient_role, or mfa_required. Check the error code and effective permissions.",
"request_id": "req_example"
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in the current organization.",
"request_id": "req_example"
}
}{
"error": {
"code": "conflict",
"message": "The name is taken, the provider refused the authorization, the account is a different company than the integration is connected to, or the integration changed meanwhile.",
"request_id": "req_example"
}
}{
"error": {
"code": "rate_limit_exceeded",
"message": "The IP or authenticated credential exceeded its request limit.",
"request_id": "req_example"
}
}{
"error": {
"code": "internal_error",
"message": "Unexpected server failure. Include the request ID when contacting support.",
"request_id": "req_example"
}
}{
"error": {
"code": "service_unavailable",
"message": "Authentication infrastructure is unavailable or rate limited. Honor Retry-After when provided.",
"request_id": "req_example"
}
}Complete a provider authorization
After the provider sends the browser back, the callback returns it to the app with integration_state and integration_code in the URL fragment. Post them here with the same browser_nonce. Requires Admin and the signed-in browser session, organization and user that started the attempt. The integration is saved as not_tested: test it next. Provider codes are single-use, so a failed or repeated completion needs a new attempt.
curl --request POST \
--url http://localhost:3500/v1/integrations/authorizations/complete \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"state": "<string>",
"code": "<string>",
"browser_nonce": "<string>"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({state: '<string>', code: '<string>', browser_nonce: '<string>'})
};
fetch('http://localhost:3500/v1/integrations/authorizations/complete', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "http://localhost:3500/v1/integrations/authorizations/complete"
payload = {
"state": "<string>",
"code": "<string>",
"browser_nonce": "<string>"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"provider": "<string>",
"name": "<string>",
"status": "connected",
"syncable": true,
"enabled": true,
"auto_sync": true,
"scope": {
"suppliers": {
"mode": "all",
"items": [
{
"id": "<string>",
"name": "<string>",
"code": "<string>",
"group": {
"kind": "vendor-sites",
"prefixes": [
"<string>"
],
"site_count": 123,
"inactive_site_count": 1
}
}
],
"include_unidentified": true
},
"companies": [
{
"id": "<string>",
"name": "<string>",
"country_code": "<string>",
"accounting_currency_code": "<string>"
}
],
"processing_statuses": [
"<string>"
],
"path_globs": [
"<string>"
],
"module_company_codes": {
"costinvoice": [
"<string>"
],
"purchaseorder": [
"<string>"
]
}
},
"credentials": {
"values": {},
"secrets_set": [
"<string>"
]
},
"realtime": {
"supported": true,
"status": "active"
},
"rate_limited_until": "2023-11-07T05:31:56Z",
"last_successful_sync": {
"started_at": "2023-11-07T05:31:56Z",
"trigger": "manual"
},
"active_sync_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"provider": "<string>",
"name": "<string>",
"status": "connected",
"syncable": true,
"enabled": true,
"auto_sync": true,
"scope": {
"suppliers": {
"mode": "all",
"items": [
{
"id": "<string>",
"name": "<string>",
"code": "<string>",
"group": {
"kind": "vendor-sites",
"prefixes": [
"<string>"
],
"site_count": 123,
"inactive_site_count": 1
}
}
],
"include_unidentified": true
},
"companies": [
{
"id": "<string>",
"name": "<string>",
"country_code": "<string>",
"accounting_currency_code": "<string>"
}
],
"processing_statuses": [
"<string>"
],
"path_globs": [
"<string>"
],
"module_company_codes": {
"costinvoice": [
"<string>"
],
"purchaseorder": [
"<string>"
]
}
},
"credentials": {
"values": {},
"secrets_set": [
"<string>"
]
},
"realtime": {
"supported": true,
"status": "active"
},
"rate_limited_until": "2023-11-07T05:31:56Z",
"last_successful_sync": {
"started_at": "2023-11-07T05:31:56Z",
"trigger": "manual"
},
"active_sync_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}{
"error": {
"code": "validation_error",
"message": "Invalid request format, parameters, or body. Details contain up to 20 actionable field errors; the complete encoded request body must be at most 2 MiB (2,097,152 bytes).",
"request_id": "req_example"
}
}{
"error": {
"code": "invalid_token",
"message": "Missing or invalid bearer credential.",
"request_id": "req_example"
}
}{
"error": {
"code": "forbidden",
"message": "Access denied: forbidden, token_disabled, organization_required, insufficient_role, or mfa_required. Check the error code and effective permissions.",
"request_id": "req_example"
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in the current organization.",
"request_id": "req_example"
}
}{
"error": {
"code": "conflict",
"message": "The name is taken, the provider refused the authorization, the account is a different company than the integration is connected to, or the integration changed meanwhile.",
"request_id": "req_example"
}
}{
"error": {
"code": "rate_limit_exceeded",
"message": "The IP or authenticated credential exceeded its request limit.",
"request_id": "req_example"
}
}{
"error": {
"code": "internal_error",
"message": "Unexpected server failure. Include the request ID when contacting support.",
"request_id": "req_example"
}
}{
"error": {
"code": "service_unavailable",
"message": "Authentication infrastructure is unavailable or rate limited. Honor Retry-After when provided.",
"request_id": "req_example"
}
}Authorizations
Personal API key. Send X-Organization-Id. The required cumulative level is listed in x-watchdog-permission.
Headers
Required for personal API keys. Target one organization you have access to. Migrated keys may omit it to use their original organization. For Clerk sessions, it must match the active organization.
Body
Response
Current resource.
Result of the latest test or sync. not_tested until the first test.
connected, invalid_credentials, permission_denied, server_error, not_tested Enabled and in a status that allows a sync to start.
Nightly incremental sync, plus webhooks where supported.
Show child attributes
Show child attributes
Secrets are write-only and never returned to any role.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
The provider asked Watchdog to pause requests until this time.
Latest sync that completed with full coverage.
Show child attributes
Show child attributes