Bud Financial O Auth2 API

Retrieve and manage access and refresh tokens to authenticate to the Bud platform via OAuth2 protocol.

Business capability
Developer Identity & Credential Management BC-4270.40

Operations 1

POST /v1/oauth/token OAuth2 #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/bud-co-oauth2-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

bud-co-oauth2-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: 'Bud API Services: Documentation O Auth2 API'
  version: 2.10.10
  description: '# Overview


    ## Introduction

    Welcome to Bud''s API Platform documentation.'
  contact:
    name: Bud Support
    email: help@thisisbud.com
    url: https://www.thisisbud.com/
  x-logo:
    url: data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAATAAAABuCAQAAAAKAYdLAAAACXBIWXMAAC4jAAAuIwF4pT92AAAAB3RJTUUH4wQDDggcbXcx7wAABeJJREFUeNrt3W2IFVUcx/HvXRW1VdQedy1bZVfoYX0osVQyfSGElKbRA5oFIaIlhAkWUYm6gvqqDMHMoBeKlhayCCZC2AMRPay7aJrSZmauZhQqaj7t7u1Fi965987s7D1n7pk7/j73zX2Y85//mXt2Zu45Z2ZBREREREREREREREREREREREREREREREREREREREREREREREREROIiZSFGH+YxgsOs5U/X1bFiPDPpQT3bu1DmcaZyg+vErWpjD+s47zoN6Mte0qRJc4Iq18lYMJv2jvosD11mRUeJpD32UO7664BFGQl94DoZY704fbU2rQwKVWYwbc6bQlSPBaYbtMz4K7nP53lpGkK/q8+7MTxUmeEWtmJcGX+j5psmM0I3l9vCirKAV36OuE46QsbfaHL/9opnL9tcpxBf3V0nkAgzWMRj9HadhrH+3Gk7pBqYDZdY3oXfnHE2gc1U2gyoQ6Rk+pKZdgOqgYnXF7TYDGe3gcWgW85QH9cJxMAVm8HsNrBqhhV1U9g33XUCzo1gsM1wdhtYio8ZWsytYdksFrpOwbGhbLYb0PavyLs5wA+c9v28lRa+Zzt/+y5RwwKqaOCdgCjZRvEit/A1a7jou8xwJjOMAb7D+ylqqCmw1imeZ0oCBrv7Mzp+/QofFTDCdZG13Jw3Wi1nOpbZT9+QGUziUkeZ3T49z+P4pqCRuCkhM1jjfMwwqsdG182rsAaWJs0JxuWJ9knGEq+EzODHjDLTcj5NsbjgwehwDazm6vyL5D2MG5i7booKdjE25917M57XhoxUG1hmJUsjrmWtlVl18ZQ2DeCyH6ycT7kpIJ+wuQWVeZJXI69HcpsXHDQN4LajtZIlkcbvzWqn9St1R3nPNIT93wzt/MSZPO+nqKA65699Nos5FdHmgZkMzHnvIj9zLm9+Q7jd0nqP8VtkdSqWNppYxT+u08g+yW8OnKRXw4ac08hnPUscyvjkw5AZXM4os9jzyY6sdZ3h5YC++jLm0lrASf50T5krzEn0QbOLbB8in2FvwKfNPJczCXd0hLV7wPPqL8bybt691//aWWfhkPo2681PjZPDbgP7lYZOl1nNJs9rW4elXD2zfkK8wIFOy2w1XuuWyOpTkuw2sHOhlqrzvIqu59gbuYEdIcqcjSyb65SLX5EHOepgrbuKtJ6nHNQtxtx0U5xM8DoXMkez7K5xM7Tp4iS4WOvszvss5feSP9Fvo5EVnDDfHGJfpd157Y48xFRGmfaEaWcu/qqYZxpCDcxcqR8Mg9xlGkANzNz+BDcx4zEJNTBzv5gPCSeXTvJtmM+3PJqIKdNj6GE3pJsG5mIwOMp1ptnABgd1sq+G7ebnXZncHCKjG3+M1zpLTzMz7AZ00cBG5pmlFb3JmkQTSpPd21HZbWD9Qy21zPPK/zricNH6+B7mvZFreTpEtAFWt0dpsnoWZreBVTG+kyVS1GVN4/vDd9lJVIRY5yzfPdPlrPHHdTwYItr1bkLcTia8M1qPM9F3yRRjcuaYprNmHxzyfNbQyQlnGTM47ynhndFan7WuCywLODz35I2sC9DCXheZHBNpsXvZmu1fkZXs5rjPnPzb8hyAzrIzINr9HOBIwNXat+ZcleS1hame1714izc55jNvbVDBtz7pyWuJuI15P/tnx1F0UwzsQpprO5nil2KIQSZbqcspnwp57+iu2MQT1mMmhNue/MMR3xfwMi8VYRhnmJqXP/MG1lZwyVNMy9l/FR4tf/mdvB553Uz2sXFn+n1YaGCNBZZr5mH25by7xzCb3PKrmM+lgmK1BV4hdc0+2g2zjq8m1wlAOY1dvqXGKep87oZYzUmDW3Vs8+myuIf6Am6AsiT0Nljp/CYl0Twaze9ZaaN3u5w5jAy5L2ylhe/4nAu+S1Qwl+oCsrjCV2wM2KXfwSPUcmPIGv9LPZ91Ye1TEnEb80ztNLE+Dv8MS0RERERERERERERERERERERERERERERERERERERERERERERERERs+Q/rhi5WauEgfQAAAABJRU5ErkJggg==
servers:
- url: https://api-sandbox.thisisbud.com
tags:
- name: OAuth2
  x-displayName: OAuth2
  description: Retrieve and manage access and refresh tokens to authenticate to the Bud platform via OAuth2 protocol.
paths:
  /v1/oauth/token:
    post:
      tags:
      - OAuth2
      summary: OAuth2
      description: 'This endpoint is used to create access and refresh tokens.


        The access token is used as a bearer token to authenticate requests to Bud endpoints;

        the refresh token is used to generate a new access token without the need to supply your client credentials again.


        The access token usually expires after the `expires_in` time (in seconds) has elapsed.

        However this is not guaranteed, so it is recomended to integrate such as to handle the `401` response code and refresh the token when it this response code is seen.


        Refresh tokens typically expire after 24 hours, but this is not guaranteed.


        > **🚧** Recognise the sensitive nature of access tokens. Implement appropriate security measures to prevent unauthorized access.


        Related Guides:

        - https://docs.thisisbud.com/docs/authentication'
      operationId: oauth_token_post
      security:
      - Basic: []
      parameters:
      - in: header
        name: Content-Type
        required: true
        schema:
          type: string
          enum:
          - application/x-www-form-urlencoded
      - $ref: '#/components/parameters/ClientId'
      - in: header
        name: authorization
        schema:
          type: string
          description: "The `authorization` header is used to send the client credentials in the form of a base64 encoded string. \nThe format of the string is `client_id:client_secret`.\n\nThis is only required when retrieving an auth token and not whilst refreshing an auth token.\n\nExample: `Basic Y2xpZW50X2lkOmNsaWVudF9zZWNyZXQ=`\n"
          example: Basic Y2xpZW50X2lkOmNsaWVudF9zZWNyZXQ=
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              oneOf:
              - title: When Retrieving an Auth Token
                required:
                - grant_type
                properties:
                  grant_type:
                    type: string
                    enum:
                    - client_credentials
              - title: When Refreshing an Auth Token
                required:
                - grant_type
                - refresh_token
                properties:
                  grant_type:
                    type: string
                    enum:
                    - refresh_token
                  refresh_token:
                    type: string
                    description: The `refresh_token` received when initially retieving an auth token.
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RetrieveAuthTokenResponse'
              example:
                operation_id: oauth_token_create
                data:
                  access_token: RJptkI22inJMLGmRvdUWUj02WA6cuV0P2cPAF1OkG5F2FAh41hkbGw26v419M7me4qCfsu4pZwfjxB6wOO42dJeTnTAv41C4CnR0Mkism1fwbg6trIo5lNixX1roWD4gZkG8W1Mp4cjaPWe41sc9S61Jmt6TvMgXJ3VRxqnSR9UVlaF7oeJPLwi7sHHcKuaiLrNflwEDE2aZNDVHqmNeiDFrY8GQAzNCQLevqkMKGDsnRtoD2EqX8YKu6G2z3Vr
                  token_type: Bearer
                  expires_in: 3600
                  refresh_token: XO9haFEajZaEqYY8wJUkdsVWG2b3r6jY1aXdsbhNtgmiz4K6e78hZt73kTQjuO57sVo8T6xHAjxk6Day0utTpHnXzUrKy7GSESsmxJoKzcCZeXdJCQLQvyXLSYMlMf3OZVpwcwJp7fnpCARdhmP0oLocSEnTSh60FBO2HQCnseFT6DgtSTsODbx8HC230epKAbkyOeGkC2gWQctXAFb1dNa8r1W8RzPWGe5a6wkAUH2rQiv7RjIA7Eoy663Sf9Q
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServerErrorResponse'
              examples:
                Basic Auth Credentials Incorrect:
                  value:
                    operation_id: unknown
                    code_id: unknown
                    message: Unauthorised request
                Basic Auth Missing:
                  value:
                    operation_id: oauth_token_create
                    code_id: failed_validation
                    message: could not extract basic auth headers
                Grant Type Missing/Incorrect or Content Type missing:
                  value:
                    operation_id: oauth_token_create
                    code_id: failed_validation
                    message: could not extract basic auth headers
                    errors:
                      grant_type: grant_type must be one of [client_credentials refresh_token]
        '401':
          description: Unauthorised
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServerErrorResponse'
              example:
                operation_id: oauth_token_create
                code_id: unauthorised
                message: Unauthorised.
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServerErrorResponse'
              example:
                operation_id: oauth_token_create
                code_id: forbidden
                message: Forbidden.
        '500':
          description: Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServerErrorResponse'
              example:
                operation_id: unknown
                code_id: unknown
                message: 'An error occurred while processing your request. Get in touch with us and provide us your request id: 7ef63242-ba6d-4661-8014-f9eaa9cb2ad8'
components:
  schemas:
    ServerErrorResponse:
      title: Server Error Response
      type: object
      required:
      - operation_id
      - code_id
      - message
      properties:
        operation_id:
          $ref: '#/components/schemas/OperationId'
        code_id:
          type: string
          description: A descriptive enough string that is linked to the reason for the error.
        message:
          type: string
          description: An actual user friendly error message.
        errors:
          anyOf:
          - $ref: '#/components/schemas/Error'
          - $ref: '#/components/schemas/Errors'
    RetrieveAuthTokenResponse:
      title: Retrieve Auth Token Response
      required:
      - operation_id
      - data
      properties:
        operation_id:
          type: string
          enum:
          - oauth_token_create
        data:
          type: object
          required:
          - access_token
          - token_type
          - expires_in
          - refresh_token
          properties:
            access_token:
              type: string
              description: A short-lived token that is used to authenticate requests to Bud endpoints.
            token_type:
              type: string
              description: The type of token provided in the `access_token` field (typically `Bearer`).
            expires_in:
              type: integer
              description: The amount of time (in seconds) in which the `access_token` will expire.
            refresh_token:
              type: string
              description: A long-lived token that can be used to obtain a new `access_token` when the current `access_token` expires.
    Errors:
      title: Array of Error Object
      description: Contains a list of error messages
      type: object
      additionalProperties:
        type: array
        items:
          type: string
    OperationId:
      title: Operation Id Field
      type: string
      description: A unique identifier/reference associated with a given endpoint/operation
    Error:
      title: Error Object
      type:
      - object
      - 'null'
      description: Contains a field specific error message
      additionalProperties:
        type: string
  parameters:
    ClientId:
      in: header
      name: X-Client-Id
      schema:
        type: string
      required: true
      description: The API Client Identifier (Service Application Identifier).
      example: 8711bbef-b357-4c2d-97ca-0d9df4206e9a
  securitySchemes:
    Basic:
      type: http
      scheme: basic
    OAuth2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: /v1/oauth/token
          scopes: {}
      description: "\nAuthentication flow:\n\n1. Perform OAuth2 Client Credentials authentication using API Credentials (`client_id`,`client_secret`) to obtain an `access_token` against `/v1/oauth/token` endpoint,\n2. Use `access_token` as Bearer Authorisation for every other API request,\n3. Include `X-Client-Id` (=client_id) within the header of every API request,\n4. Note that some of the requests may also require `X-Customer-Id` to be provided within the request header.\n\n### Examples\nObtain OAuth2 `access_token` and `refresh_token` using `grant_type=client_credentials` and HTTP Basic auth header\n\n```\ncurl --basic --user {{client_id}}:{{client_secret}} \\\n  -X POST https://api-sandbox.thisisbud.com/v1/oauth/token \\\n  -H 'Content-Type: application/x-www-form-urlencoded' \\\n  -d grant_type=client_credentials\n```\n\nSuccessful response:\n```\n{\n  \"operation_id\": \"oauth_token_post\",\n  \"data\": {\n    \"access_token\": \"dd0c17e3fd6d2ce94aa091257a3ea393b4f9b5cf3d3e998f07dc9826da86ff15\",\n    \"token_type\": \"bearer\",\n    \"expires_in\": 3600,\n    \"refresh_token\": \"fac32cca7559d9f6e8f1dfe9a99c71fa1dcfeb482bedf287d7934d2667ae54b3\"\n  }\n}\n```\n\nRefresh `access_token` token using `refresh_token` against `/v1/oauth/token` endpoint with `grant_type=refresh_token`\n\n```\ncurl -X POST \\\n  https://api-sandbox.thisisbud.com/v1/oauth/token \\\n  -H 'Content-Type: application/x-www-form-urlencoded' \\\n  -H 'X-Client-Id: {{client_id}}' \\\n  -d 'grant_type=refresh_token&refresh_token={{refresh_token}}'\n```\n\nSuccessful response:\n```\n{\n    \"operation_id\": \"oauth_token_post\",\n    \"data\": {\n        \"access_token\": \"cc0c17e3fd6d2ce94aa091257a3ea393b4f9b5cf3d3e998f07dc9826da86ff94\",\n        \"token_type\": \"bearer\",\n        \"expires_in\": 3600,\n        \"refresh_token\": \"ffc30cca7559d9f6e8f1dfe9a99c71fa1dcfeb482bedf287d7934d2667ae54b3\"\n    }\n}\n```\n"
x-tagGroups:
- name: ''
  tags:
  - OAuth2
  - Authentication
- name: ''
  tags:
  - Create a Connection
  - Manage a Connection
  - Ingest First Party Data
  - Connect API
- name: ''
  tags:
  - Manage Customers
  - Customers API
- name: ''
  tags:
  - Enrichment Resources
  - Enrichment Totals
  - Enrichment API
- name: ''
  tags:
  - Retrieve Financial Data
  - Manage Financial Data
  - Correct Financial Data
  - Financial Data API
- name: ''
  tags:
  - Spending Budgets
  - Savings Goals V2
  - Goals API
- name: ''
  tags:
  - Regular Payments Finder
  - Income Finder
  - Loan Finder
  - Debt Collection Finder
  - Product Finder
  - Subscription Finder
  - Smart Finders API
- name: ''
  tags:
  - Transaction Search
  - Intelligent Search API
- name: ''
  tags:
  - Customer Applications
  - Customer Application Links
  - Aggregation Buckets
  - Retrieve Affordability Report V2
  - Retrieve Affordability Report
  - Retrieve Affordability Risk Insights
  - Assess API
- name: ''
  tags:
  - Initiate Payment - Bud license
  - Initiate Payment - Client license
  - Manage Payments
  - Payments API
- name: ''
  tags:
  - Retrieve Customer Characteristics
  - Characteristics API
- name: ''
  tags:
  - Retrieve Actionable Insights
  - Custom Insights
  - Frontend Widgets
  - Insights API