Convert OAuth Authorization API

Delegated authorization endpoints for third-party OAuth clients. Typical flow: * OAuth client initiates GET request in browser (`/oauth/authorize`) with `client_id` + `response_type=code` + `scope` + `state` + `code_challenge` (PKCE) * While generating `code_challenge` — don't forget to store the `code_verifier` which will be used to obtain the access token * User authenticates in Convert and approves scope in consent UI * OAuth client exchanges one-time code (`/auth/oauth/token`) for a scoped bearer session token * User can list/revoke authorized OAuth sessions (`/auth/oauth/sessions*`) Scopes: `selected_accounts_projects` Example: ``` https://app.convert.com/auth/oauth/authorize?client_id=1111111&scope=selected_accounts_projects&response_type=code ```

Operations 1

POST /auth/oauth/token Exchange OAuth code for session token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/convert-oauth-authorization-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

convert-oauth-authorization-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Convert OAuth Authorization API
  description: Move your app forward with the Convert API.
  version: 2.0.0
servers:
- url: https://api.convert.com/api/v2
  description: Live API server
- url: https://apidev.convert.com/api/v2
  description: DEV API server
- url: http://apidev.convert.com:5000/api/v2
  description: DEV mocked API server
tags:
- name: OAuth Authorization
  description: Delegated authorization endpoints for third-party OAuth clients.
paths:
  /auth/oauth/token:
    post:
      operationId: requestOauthToken
      summary: Exchange OAuth code for session token
      description: 'Public endpoint used by OAuth clients to exchange a one-time authorization code for a scoped bearer session token.

        Enforces PKCE binding.'
      tags:
      - OAuth Authorization
      requestBody:
        $ref: '#/components/requestBodies/OAuthTokenRequest'
      responses:
        '200':
          $ref: '#/components/responses/OAuthTokenResponse'
        default:
          $ref: '#/components/responses/ErrorResponse'
components:
  schemas:
    ErrorData:
      type: object
      properties:
        code:
          type: integer
          format: int32
        message:
          oneOf:
          - type: string
          - type: array
            items:
              type: string
        fields:
          oneOf:
          - type: string
          - type: array
            items:
              type: string
    OAuthScopeMode:
      type: string
      enum:
      - selected_accounts_projects
    OAuthScopeAccountResponse:
      type: object
      required:
      - account_id
      properties:
        account_id:
          type: integer
          minimum: 1
        name:
          description: Display name of the account.
          type: string
        projects:
          type: array
          items:
            $ref: '#/components/schemas/OAuthScopeProject'
    OAuthTokenRequestData:
      type: object
      required:
      - grant_type
      - code
      - client_id
      - code_verifier
      properties:
        grant_type:
          description: Authorization grant type.
          type: string
          enum:
          - authorization_code
          default: authorization_code
        code:
          description: One-time authorization code from consent redirect.
          type: string
          minLength: 1
        client_id:
          description: Identifier of the OAuth client application that initiated the authorization request.
          type: string
        code_verifier:
          description: PKCE verifier for code challenge validation.
          type: string
          minLength: 43
          maxLength: 128
          pattern: ^[A-Za-z0-9\-._~]+$
    OAuthScopeResponse:
      type: object
      required:
      - mode
      properties:
        mode:
          $ref: '#/components/schemas/OAuthScopeMode'
        accounts:
          type: array
          items:
            $ref: '#/components/schemas/OAuthScopeAccountResponse'
    OAuthScopeProject:
      type: object
      required:
      - project_id
      - role
      properties:
        project_id:
          type: integer
          minimum: 1
        role:
          description: User's role for this project.
          type: string
        name:
          description: Display name of the project.
          type: string
    OAuthTokenResponseData:
      type: object
      required:
      - access_token
      - token_type
      - expires_at
      - scope
      properties:
        access_token:
          description: Opaque OAuth session bearer token.
          type: string
        token_type:
          type: string
          enum:
          - Bearer
        expires_at:
          type: integer
          description: Absolute expiration timestamp (unix seconds).
        scope:
          $ref: '#/components/schemas/OAuthScopeResponse'
  responses:
    ErrorResponse:
      description: 'Indicates an error occurred while processing the request. The `code` provides an HTTP status code, `message` offers a human-readable explanation or an array of validation errors, and `fields` (if present) specifies which input fields were problematic.

        '
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorData'
    OAuthTokenResponse:
      description: One-time code exchanged for a scoped OAuth bearer session token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/OAuthTokenResponseData'
  requestBodies:
    OAuthTokenRequest:
      required: true
      description: Exchanges a one-time authorization code for an OAuth bearer session token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/OAuthTokenRequestData'
  securitySchemes:
    requestSigning:
      type: apiKey
      x-name-applicationId: Convert-Application-ID
      x-name-expire: Expire
      name: Authorization
      in: header
      description: 'See **[API Key Authentication](#tag/API-KEY-Authentication)** for more information.

        '
    secretKey:
      type: http
      scheme: bearer
      description: 'See **[API Key Authentication](#tag/API-KEY-Authentication)** for more information.

        '
    cookieAuthentication:
      type: apiKey
      in: cookie
      name: sid
      description: Cookie authentication is used against Convert's own IdentityProvider  or third party identity providers and is described more in the "[Cookie Authentication](#tag/Cookie-Authentication)" section
x-tagGroups:
- name: Client Authentication
  tags:
  - API KEY Authentication
  - Cookie Authentication
  - OAuth Authorization
- name: Common Parameters
  tags:
  - Optional Fields
  - Expandable Fields
- name: Requests
  tags:
  - User
  - Accounts
  - AI content
  - Collaborators
  - API Keys
  - Projects
  - SDK Keys
  - Experiences
  - Experience Variations
  - Experience Sections
  - Section Versions
  - Version Changes
  - Experiences Reports
  - Experiences Heatmaps
  - Goals
  - Hypotheses
  - Knowledge Bases
  - Observations
  - Locations
  - Audiences
  - Domains
  - Cdn Images
  - Files
  - Tags
  - Features
  - Visitor Insights
  - Visitors Data
  - Visitor Data Placeholders
  - OAuth