Tokens
All token calls go from your server to https://api.splashifypro.com/api/v1/oauth/token. Never call it from a browser or a mobile app: it needs your client secret.
Tokens are random strings, not JWTs. Do not try to read anything from them.
Client authentication
Send your Client ID and secret in one of two ways:
- HTTP Basic (preferred):
Authorization: Basic base64(client_id:client_secret).curl -u "spo_app_...:spo_cs_..."does this for you. - In the body:
client_idandclient_secretfields.
A secret in the query string is refused. Bodies can be application/x-www-form-urlencoded or application/json.
Swap the code
curl -X POST https://api.splashifypro.com/api/v1/oauth/token \
-u "spo_app_XXXX:spo_cs_YYYY" \
-d grant_type=authorization_code \
-d code=spo_ac_ZZZZ \
-d redirect_uri=https://yourapp.example/splashify/callback \
-d code_verifier=VERIFIER{
"access_token": "spo_at_...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "spo_rt_...",
"scope": "account:read whatsapp.messages:send whatsapp.templates:read",
"account_id": "6f1c2a8e-...",
"platform": "whatsapp"
}Save the refresh token (encrypted) against account_id. scope is what the token can do right now: permissions that need a verified app are left out while your app is not verified.
A code works once. If the same code is used again by your app, we sign out the tokens it gave, because someone may have copied it.
Refresh
curl -X POST https://api.splashifypro.com/api/v1/oauth/token \
-u "spo_app_XXXX:spo_cs_YYYY" -d grant_type=refresh_token -d refresh_token=spo_rt_BBBBThe answer has the same shape, with a new refresh token. Rules:
- Save the new refresh token every time, before you use the new access token. The old one stops working the moment it is used.
- A spent refresh token used again within 10 seconds (for example a retry after a lost answer) gets
invalid_grantand changes nothing. Ask the user to connect again if you lost the new one. - A spent refresh token used again after 10 seconds looks like a stolen token: we sign out that connection's tokens, email you a security alert and answer
invalid_grant. The user has to connect again. - At most 60 refreshes an hour per connection.
Narrow the permissions
Add scope to a refresh to get tokens with fewer permissions, for example a token that can only read templates:
-d grant_type=refresh_token -d refresh_token=spo_rt_BBBB -d "scope=whatsapp.templates:read"The list must be part of what the account allowed. account:read is always kept. A refresh can never add permissions: for more, send the user to the authorize page again.
Revoke
curl -X POST https://api.splashifypro.com/api/v1/oauth/revoke \
-u "spo_app_XXXX:spo_cs_YYYY" -d token=spo_rt_BBBB -d revoke_grant=trueThe answer is always 200 {} once your client is authenticated, even for a token that is unknown or already revoked. Revoking a refresh token signs out the tokens it came with.
Who is connected
curl https://api.splashifypro.com/api/v1/oauth/me -H "Authorization: Bearer spo_at_AAAA"{
"account_id": "6f1c2a8e-...",
"platform": "whatsapp",
"name": "Asha Traders",
"scopes": ["account:read", "whatsapp.messages:send"],
"client_id": "spo_app_XXXX"
}Token errors
After 10 failed client authentications in 10 minutes from one IP address, that address is blocked for your Client ID for 15 minutes. Other addresses are not affected.
The Email platform
Everything on this page is the same for Email apps. Only the authorize host differs (email.splashifypro.com), and platform is email.