Qonto OAuth API

The OAuth API from Qonto — 1 operation(s) for oauth.

Documentation

📖
Documentation
https://docs.qonto.com/api-reference/introduction
📖
APIReference
https://docs.qonto.com/api-reference/business-api/accounts-organizations/organizations/retrieve-the-authenticated-organization-and-list-bank-accounts
📖
APIReference
https://docs.qonto.com/api-reference/business-api/transactions-statements/transactions/list-transactions
📖
Documentation
https://docs.qonto.com/api-reference/business-api/payments-transfers/sepa-transfers/introduction
📖
Documentation
https://docs.qonto.com/api-reference/business-api/payments-transfers/international-transfers/introduction
📖
APIReference
https://docs.qonto.com/api-reference/business-api/payments-transfers/internal-transfers/create-an-internal-transfer
📖
APIReference
https://docs.qonto.com/api-reference/business-api/cards/list-cards
📖
Documentation
https://docs.qonto.com/api-reference/business-api/expense-management/client-quotes-notes/introduction-factur-x
📖
APIReference
https://docs.qonto.com/api-reference/business-api/expense-management/supplier-invoices/list-supplier-invoices
📖
Documentation
https://docs.qonto.com/api-reference/business-api/payments-transfers/sepa-direct-debit/introduction
📖
Documentation
https://docs.qonto.com/api-reference/business-api/payments-transfers/payment-links/introduction
📖
Documentation
https://docs.qonto.com/api-reference/business-api/terminals/introduction
📖
Documentation
https://docs.qonto.com/api-reference/business-api/webhooks/overview
📖
APIReference
https://docs.qonto.com/api-reference/business-api/webhooks/supported-webhooks/v1-transactions
📖
APIReference
https://docs.qonto.com/api-reference/onboarding-api/endpoints/registrations/create-a-registration
📖
Documentation
https://docs.qonto.com/api-reference/sdk-libraries/doc-pages/overview
📖
APIReference
https://docs.qonto.com/api-reference/business-api/endpoints/encoded-requests/introduction

Specifications

Other Resources

OpenAPI Specification

qonto-oauth-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Qonto Business Cards OAuth API
  description: Business banking API for Qonto - programmatic access to business accounts, EUR transactions, SEPA and international transfers, cards, client and supplier invoices, SEPA Direct Debit, payment links, terminals, and webhooks. Authenticated with a login+secret-key API key or OAuth 2.0. Modeled from public documentation.
  version: v2
  contact:
    name: Qonto Developers
    url: https://docs.qonto.com/
  termsOfService: https://qonto.com/en/legal
servers:
- url: https://thirdparty.qonto.com
  description: Production
- url: https://thirdparty-sandbox.staging.qonto.co
  description: Sandbox
security:
- SecretKey: []
- OAuth: []
tags:
- name: OAuth
paths:
  /oauth2/token:
    post:
      operationId: createOrRefreshTokens
      tags:
      - OAuth
      summary: Create or refresh OAuth 2.0 tokens
      description: Exchange an authorization code (or a refresh token) for an access token (valid 1 hour), plus a refresh token (valid 90 days) when offline_access is requested and an ID token when openid is requested. Must be called from your backend so the client secret is never exposed.
      security: []
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              required:
              - grant_type
              - client_id
              - client_secret
              properties:
                grant_type:
                  type: string
                  enum:
                  - authorization_code
                  - refresh_token
                client_id:
                  type: string
                client_secret:
                  type: string
                code:
                  type: string
                refresh_token:
                  type: string
                redirect_uri:
                  type: string
                  format: uri
      responses:
        '200':
          description: Token set
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TokenSet'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  responses:
    Unauthorized:
      description: Missing or invalid authentication
  schemas:
    TokenSet:
      type: object
      properties:
        access_token:
          type: string
        token_type:
          type: string
          example: bearer
        expires_in:
          type: integer
          example: 3600
        refresh_token:
          type: string
        id_token:
          type: string
        scope:
          type: string
  securitySchemes:
    SecretKey:
      type: apiKey
      in: header
      name: Authorization
      description: 'Qonto API key. Value is the organization sign-in and secret key concatenated with a colon - "Authorization: {sign-in}:{secret-key}". This resembles HTTP Basic auth but is NOT - the value is not Base64 encoded.'
    OAuth:
      type: oauth2
      description: OAuth 2.0 authorization code flow. Access tokens are valid 1 hour; refresh tokens 90 days (offline_access). Bearer access token sent in the Authorization header.
      flows:
        authorizationCode:
          authorizationUrl: https://oauth.qonto.com/oauth2/auth
          tokenUrl: https://thirdparty.qonto.com/oauth2/token
          scopes:
            openid: OpenID Connect ID token
            offline_access: Issue a refresh token
            organization.read: Read organization, accounts, memberships, labels, transactions
            membership.read: Read the authenticated membership
            membership.write: Create memberships
            team.read: Read teams
            team.write: Create teams
            subscription.read: Read the organization subscription plan
            card.read: Read cards
            card.write: Manage cards
            payment.write: Create SEPA transfers and manage beneficiaries
            internal_transfer.write: Create internal transfers
            international_transfer.write: Create international transfers and beneficiaries
            beneficiary.trust: Trust SEPA beneficiaries
            attachment.read: Read attachments
            attachment.write: Upload attachments
            client.read: Read clients (customers)
            client.write: Manage clients (customers)
            client_invoices.read: Read client invoices, quotes, credit notes
            client_invoice.write: Manage client invoices, quotes, credit notes
            supplier_invoice.read: Read supplier invoices
            supplier_invoice.write: Manage supplier invoices
            product.read: Read products
            product.write: Manage products
            sepa_direct_debit.read: Read SEPA Direct Debit collections/mandates
            sepa_direct_debit.write: Manage SEPA Direct Debit mandates/subscriptions
            payment_link.read: Read payment links
            payment_link.write: Manage payment links
            terminal.read: Read terminals and terminal payments
            terminal.write: Create terminal payments
            einvoicing.read: Read e-invoicing settings
            insurance_contract.read: Read insurance contracts
            insurance_contract.write: Manage insurance contracts
            embed_auth_link.write: Create Embed Auth Links
            webhook: Manage webhook subscriptions