API documentation
Equipe Online API, version 2
Equipe Online publishes show schedules, start lists and results for equestrian competitions. This API is how you build on that: read the documents and results for the riders someone has given you access to, follow riders and horses, and be told when results arrive.
Everything lives under https://online.equipe.com. Requests and responses are JSON,
and every request needs an access token. Getting one takes an application and a
short review, because we want to know who is calling.
- Getting started
- Which authentication do I need
- Personal access tokens
- OAuth 2.0
- Sign in with Equipe
- Scopes
- Making requests
- Endpoint reference
- Errors
- What a token cannot do
- Getting help
Getting started
The shortest path from nothing to a working request is a personal access token. It takes three steps.
- Apply for developer access at https://online.equipe.com/developer_application/new. Tell us what you are building and which company or person is behind it. We read every application and answer by email.
- Create a key once you are approved. Your developer page links to API keys; pick the scopes you need and copy the key. It is shown once and stored hashed, so if you lose it you create a new one.
- Call the API with the key as a bearer token.
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/profiles
That returns the riders your account has been given access to. If the list is empty, connect a rider to your account first — the personal endpoints all follow from that list.
Two things to know before you build. The API is not for building something Equipe already offers. An app that competes with our own products will not be approved. And developer access is ours to give and ours to take back. We can withdraw it at any time, and when we do we will tell you why.
Which authentication do I need
Two kinds of token reach the API, and the difference is whose data you are reading.
| Personal access token | OAuth application | |
|---|---|---|
| Acts for | Your own account | Any Equipe user who authorizes you |
| How you get it | You create it yourself | The user is sent to Equipe and approves |
| Lifetime | Until you revoke it | 2 hours, then refreshed |
| Revoked by | You | The user, at any time |
| Good for | A script, a cron job, your own integration | A product other people sign in to |
If you are collecting results for your own club, take a personal access token. If you are building something riders log in to, you want OAuth.
Personal access tokens
A personal access token is a key you make for yourself. It carries your own access: the riders connected to your account, your documents, your notifications. Treat it like a password, because it is one.
- Choose
read,writeor both when you create it. Nothing else. - It does not expire. It stops working when you revoke it, and not before.
- There is no refresh token, because there is nothing to refresh.
- We show it once. We keep a hash, so we cannot show it to you again and neither can anyone who reads our database.
- Revoking one takes effect on the next request.
Give each integration its own key. Then revoking the one that leaked does not stop everything else you run.
OAuth 2.0
Use OAuth when your product acts for other Equipe users. They stay in control: they see what you are asking for, they approve it, and they can take it back.
We support the authorization code flow. There is no implicit flow, no password grant and no client credentials grant.
Applications are confidential, and we send no CORS headers. The token exchange uses your client secret, so it has to happen on your server. A browser-only client cannot complete it.
Register an application
Approved developers register applications on their developer page. You give the name and description people see when they authorize you, a website and privacy policy, a support address, and one redirect URI per line. You get a client id and a client secret; the secret is shown once.
Send the user to Equipe
GET https://online.equipe.com/oauth/authorize
?client_id=YOUR_CLIENT_ID
&redirect_uri=https://example.com/callback
&response_type=code
&scope=read
&state=RANDOM_STRING
| Parameter | Description |
|---|---|
client_id | From your registered application. Required. |
redirect_uri | Must match one you registered, exactly. Required. |
response_type | code. Required. |
scope | Space separated. Defaults to read. |
state | Returned to you unchanged. Use it, and check it. |
code_challenge | PKCE, see below. |
code_challenge_method | S256 or plain. |
If they are not signed in we ask them to, and bring them back. Then they see who
is asking, what you say your application does, links to your site and privacy
policy, and the list of things you want to be allowed to do. Denying sends them
back to your redirect URI with error=access_denied.
Exchange the code
Approving sends them to your redirect URI with ?code=…&state=…. The
code is good for ten minutes and once.
curl -X POST https://online.equipe.com/oauth/token \
-d grant_type=authorization_code \
-d code=RETURNED_CODE \
-d redirect_uri=https://example.com/callback \
-d client_id=YOUR_CLIENT_ID \
-d client_secret=YOUR_CLIENT_SECRET
{
"access_token": "…",
"token_type": "Bearer",
"expires_in": 7200,
"refresh_token": "…",
"scope": "read",
"created_at": 1786042773
}
Refresh, and the one rule about it
Access tokens last 2 hours. Trade the refresh token for a new pair before or after it runs out — the user is not involved.
curl -X POST https://online.equipe.com/oauth/token \
-d grant_type=refresh_token \
-d refresh_token=YOUR_REFRESH_TOKEN \
-d client_id=YOUR_CLIENT_ID \
-d client_secret=YOUR_CLIENT_SECRET
Refresh tokens rotate. Every refresh gives you a new refresh token and retires the old one as soon as the new access token is used. Store the new one and forget the old. If an old refresh token turns up again we treat it as a copy and reject the exchange, which means a client that retries with a stale token loses the whole chain and has to ask the user again.
PKCE
We accept S256 and plain. It is not required, and we
recommend it anyway: send code_challenge and
code_challenge_method with the authorize request, and
code_verifier with the exchange.
Giving a token back
curl -X POST https://online.equipe.com/oauth/revoke \
-d token=THE_TOKEN \
-d client_id=YOUR_CLIENT_ID \
-d client_secret=YOUR_CLIENT_SECRET
POST /oauth/introspect tells you whether a token is still good, and
GET /oauth/token/info describes the token you are holding. Users
manage what they have authorized from their own account page, and revoking there
stops your access immediately.
Sign in with Equipe
On top of OAuth we speak OpenID Connect, so people can sign in to your product with their Equipe account. Any standard OIDC library will do the work if you point it at our discovery document.
https://online.equipe.com/.well-known/openid-configuration
That document is the authority. If anything here disagrees with it, believe the document.
- Issuer:
https://online.equipe.com - Public keys:
https://online.equipe.com/oauth/discovery/keys - User info:
https://online.equipe.com/oauth/userinfo
Ask for the openid scope, plus profile and
email for the claims you need. You can ask for read or
write in the same breath, and the consent screen lists all of it
together.
| Claim | Scope | What it is |
|---|---|---|
sub | openid | The account id, as a string. Stable. Key your users on it. |
name | profile | The name on the account |
email | email | The email address |
email_verified | email | Always true: signing in to Equipe means receiving a code at that address |
The claims are in the id_token and at the user info endpoint alike.
curl -H "Authorization: Bearer $ACCESS_TOKEN" \
https://online.equipe.com/oauth/userinfo
{
"sub": "1",
"name": "Jon Stenqvist",
"email": "jon@example.com",
"email_verified": true
}
Scopes
A token carries scopes, and scopes decide what it may do. These are the words the user sees when they authorize your application.
| Scope | What the user is asked to allow |
|---|---|
read |
Read your results, documents and schedules |
write |
Follow riders, manage notifications and upload files on your behalf |
openid |
Know who you are on Equipe |
profile |
See your name |
email |
See your email address |
read and write reach the API. openid,
profile and email are about identity and are only useful
for signing in. An application may only ask for scopes from this list.
Read and write are separate, not a ladder. A token with only
write is refused by the endpoints that need read, exactly
as the other way round. Most integrations want both.
Making requests
Send the token on every request:
Authorization: Bearer YOUR_TOKEN
Send Content-Type: application/json when you have a body, and nest the
body under the name of the thing you are working with:
{"notification_subscription": {"active": true}}, not
{"active": true}.
Timestamps are ISO 8601 in UTC.
Blank values are left out. Most responses drop keys whose value is
null, false or empty rather than sending them. A
notification that has not been read has no read key at all, so read
the absence of a key as its blank value. The rider list is the one exception: it
keeps its zeros and its false, because a follower count of zero is an
answer.
Only /api/v2/documents is paged, with
offset. Everything else returns what it has.
We do not send CORS headers, so call us from your server rather than from a browser. There is no published rate limit; use the API at a rate you would be comfortable explaining, and cache what you can.
Endpoint reference
| Endpoint | Scope | |
|---|---|---|
GET /api/v2/profiles |
read | Details |
GET /api/v2/documents |
read | Details |
GET /api/v2/results |
read | Details |
GET /api/v2/profiles/:profile_id/results |
read | Details |
GET /api/v2/starts/:start_id/score_sheets |
read | Details |
GET /api/v2/push_messages |
read | Details |
PUT /api/v2/push_messages/read_all |
write | Details |
DELETE /api/v2/push_messages/:id |
write | Details |
DELETE /api/v2/push_messages |
write | Details |
GET /api/v2/notification_subscriptions |
read | Details |
GET /api/v2/targets/:target_identifier/notification_subscriptions |
read | Details |
POST /api/v2/notification_subscriptions |
write | Details |
PATCH /api/v2/notification_subscriptions/:id |
write | Details |
DELETE /api/v2/notification_subscriptions/:id |
write | Details |
GET /api/v2/meeting_classes/:meeting_class_id/attachments |
read | Details |
POST /api/v2/meeting_classes/:meeting_class_id/attachments |
write | Details |
DELETE /api/v2/attachments/:id |
write | Details |
GET /api/v2/users/:id |
read | Details |
Riders
The riders the account has been given access to. This is the list every other personal endpoint is scoped by: documents and notifications follow from it.
| Field | Description |
|---|---|
id |
Equipe Online id for the rider profile |
name |
Rider name |
target_identifier |
The identifier used to follow this rider elsewhere in the API |
identifier_key |
Where the rider was identified: fei, licence, email or id |
identifier_id |
The identifier itself, for example an FEI id |
birth_year |
Year of birth, when known |
age |
Age in whole years, when the birth year is known |
logo_id / logo_group |
Portrait reference |
private_notifications |
Whether followers need the rider to approve them |
approved_followers_count |
Followers receiving notifications, approved either way |
user_approved_followers_count |
Followers the rider approved by hand |
auto_approved_followers_count |
Followers approved automatically on a public profile |
pending_followers_count |
Follow requests waiting for the rider |
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/profiles
[
{
"id": 42,
"name": "Jessie Stenqvist",
"target_identifier": "rider_820f70fbf096631173bc380f515a0ad0",
"identifier_key": "svrf",
"identifier_id": "17860",
"birth_year": null,
"age": null,
"logo_id": "802",
"logo_group": "svrf",
"private_notifications": true,
"approved_followers_count": 21,
"user_approved_followers_count": 0,
"auto_approved_followers_count": 21,
"pending_followers_count": 2
}
]
Documents
Result lists, invoices and other documents for the riders the account has access to, newest first.
| Parameter | Description |
|---|---|
offset |
Skip this many documents. 50 are returned per request. |
| Field | Description |
|---|---|
id |
Document id |
label |
What the document is called |
pdf_logo_identifier |
Reference used to fetch the PDF itself |
created_at |
When the document was produced |
meeting_id / meeting_name |
The show it belongs to |
meeting_class_name |
The competition, when the document belongs to one |
class_section_id |
A start list in that competition, when there is one |
rider_name |
The rider the document is about |
curl -H "Authorization: Bearer $TOKEN" \
"https://online.equipe.com/api/v2/documents?offset=50"
[
{
"id": 9182,
"label": "Result list",
"pdf_logo_identifier": "8fa1c0…",
"created_at": "2026-08-02T14:11:53.000Z",
"meeting_id": 68000,
"meeting_name": "Falsterbo Horse Show",
"meeting_class_name": "145 cm Two phases",
"class_section_id": 551202,
"rider_name": "Jessie Stenqvist"
}
]
Results
Every start for the riders the account has access to, newest first. A start is here as soon as the start list is published, and the placing and result arrive with the result.
| Parameter | Description |
|---|---|
offset |
Skip this many starts. 25 are returned per request. |
| Field | Description |
|---|---|
id |
Start id |
class_section_id |
The start list this start is in |
rank |
Placing, when the competition has been ranked |
result_preview |
The result as the start list shows it: points, faults or a time |
meeting_class_start_at |
When the competition started |
meeting_name |
The show |
meeting_class_name |
The competition |
rider_name / horse_name / club_name |
Who rode what, for whom |
venue_country |
Country the show was held in |
discipline |
Discipline code, for example D for dressage or H for show jumping |
logo_id / logo_group |
Organizer logo reference |
rider_notification_identifier / horse_notification_identifier |
The identifiers used to follow this rider and horse elsewhere in the API |
curl -H "Authorization: Bearer $TOKEN" \
"https://online.equipe.com/api/v2/results?offset=25"
[
{
"id": 21485922,
"class_section_id": 1283367,
"rank": 1,
"result_preview": "68.723",
"meeting_class_start_at": "2026-08-16T11:34:00.000Z",
"meeting_name": "Ödåkra Ridsällskap",
"meeting_class_name": "Medelsvår B:5",
"rider_name": "Jessie Stenqvist",
"horse_name": "Red Zolo (SWB)",
"club_name": "Helsingborgs Fältrittklubb",
"venue_country": "SWE",
"discipline": "D",
"logo_id": "235",
"logo_group": "svrf",
"rider_notification_identifier": "rider_820f70fbf096631173bc380f515a0ad0",
"horse_notification_identifier": "horse_84a945663f765b9156b0104937cd1762"
}
]
class_section_id takes you to the start list, and the start id is the anchor on it: https://online.equipe.com/startlists/1283367#start_21485922 opens the list at that start.
The same list for one rider. The id is the one from the profiles list, and it has to be a rider your account has access to. Any other id returns nothing.
| Parameter | Description |
|---|---|
offset |
Skip this many starts. 25 are returned per request. |
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/profiles/42/results
The judged protocols of one start: every movement on the sheet with each judge's mark against it, the judges with what they each arrived at, and the result the protocol produced. Dressage and working equitation have protocols. Any other start, and one that has not been judged yet, answers with an empty list. The start has to be ridden by a rider your account has access to; any other id answers 404.
| Field | Description |
|---|---|
marking_sheet_id |
Identifies the protocol within the competition |
name / description |
What the protocol is called, and its edition, arena and maximum |
sheet_type |
A letter classifying the sheet: D is a dressage test, K a freestyle, W a working equitation test. Other letters occur. |
max_score |
The most points the sheet can give |
total / percent / rank |
The result of this protocol: for dressage the final result across the judges, for working equitation the result of that test. Percent is a string, formatted the way the result list shows it. total is the points added up, which dressage publishes and working equitation does not. |
judges[] |
judge_by is the position (C, E, H, M or B); alias is what the sheet calls that position. name and country come from the start list. |
judges[].total / percent / rank / deduction |
What that judge arrived at, when the discipline scores per judge. Working equitation scores the test, not each judge, so they are null there. |
judges[].technical_percent / artistic_percent |
Freestyle only |
items[] |
The rows of the sheet in order: position, group_no, section, keyword, place, instruction, coefficient, scale |
items[].section |
Which part of the sheet the row belongs to. technical is the movements, artistic the collective marks, and a section ending in _deduction is a deduction row. |
items[].points |
The mark from each judge, keyed by judge_by. Empty on a row nobody marks, such as the deduction row. |
items[].exclude_max_score |
True on a row that does not count towards max_score |
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/starts/21485922/score_sheets
[
{
"marking_sheet_id": "10145",
"name": "Medelsvår B:5",
"description": "Edition 2024, arena 20x60, max 470 points, time approx. 5.5 min",
"sheet_type": "D",
"max_score": 470.0,
"total": 296.0,
"percent": "62.979",
"rank": 3,
"judges": [
{
"judge_by": "C",
"alias": "C",
"name": "Annica Wiberg",
"country": "SWE",
"total": 296.0,
"percent": "62.979",
"technical_percent": null,
"artistic_percent": null,
"rank": 3,
"deduction": 0.0
}
],
"items": [
{
"position": 0,
"group_no": "1",
"section": "technical",
"keyword": "Inridning",
"place": "AX\nX\nXC",
"instruction": "Inridning i samlad galopp\nHalt - hälsning\nSamlad trav",
"coefficient": 1.0,
"scale": 10,
"exclude_max_score": false,
"points": { "C": 7 }
},
{
"position": 30,
"group_no": "3",
"section": "artistic",
"keyword": "Lösgjordhet",
"place": null,
"instruction": "Lösgjordhet (eftergift på tygeln, formen, accepterande av bettet…)",
"coefficient": 2.0,
"scale": 10,
"exclude_max_score": false,
"points": { "C": 6 }
},
{
"position": 32,
"group_no": null,
"section": "technical_deduction",
"keyword": "Poängavdrag",
"place": null,
"instruction": "Felridning första gången 2p - Felridning andra gången 4p",
"coefficient": 1.0,
"scale": 10,
"exclude_max_score": true,
"points": {}
}
]
}
]
A start usually has one protocol. Working equitation publishes one per judged test, in riding order. Every key is always present, null where the protocol has nothing to say.
Notifications
The 25 most recent notifications for the account, newest first. The response supports ETag and Last-Modified, so a conditional request costs you a 304.
| Field | Description |
|---|---|
push_messages[] |
id, alert, event, subject_id, subject_type, meeting_id, meeting_name, class_section_id, logo_id, logo_group, created_at, updated_at |
push_messages[].read |
Present and true once the notification has been read |
push_messages[].read_at |
When it was read |
push_notification |
The account's notification record: id, unread_count, timestamps |
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/push_messages
{
"push_messages": [
{
"id": 771,
"alert": "Jessie Stenqvist is next to go in 145 cm Two phases",
"event": "start",
"meeting_id": 68000,
"meeting_name": "Falsterbo Horse Show",
"class_section_id": 551202,
"created_at": "2026-08-02T14:09:00.000Z"
}
],
"push_notification": { "id": 12, "unread_count": 1 }
}
Marks every unread notification as read. Returns no content.
curl -X PUT -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/push_messages/read_all
Removes one notification. Returns no content.
curl -X DELETE -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/push_messages/771
Removes every notification for the account. Returns no content.
curl -X DELETE -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/push_messages
Following riders and horses
Everything the account follows.
| Parameter | Description |
|---|---|
target_identifier |
Only the subscription for this rider or horse |
| Field | Description |
|---|---|
notification_subscriptions[] |
id, target_identifier, title, subtitle, logo_url, status, timestamps |
notification_subscriptions[].active |
Present and true while the subscription is on |
notification_subscriptions[].status |
pending, auto_approved, user_approved, auto_rejected or user_rejected |
profile |
Only when target_identifier was given: the rider's name and whether the profile is private |
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/notification_subscriptions
The same list narrowed to one rider or horse, with the identifier in the path instead of the query string.
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/targets/rider_820f70…/notification_subscriptions
Starts following a rider or horse. On a private profile the subscription is created as pending and the rider decides; on a public one it is approved immediately.
| Parameter | Description |
|---|---|
notification_subscription[target_identifier] |
The rider or horse to follow. Required. |
notification_subscription[active] |
Whether the subscription is on |
notification_subscription[reason] |
Shown to the rider with a request on a private profile |
notification_subscription[create_enabled] |
Notify when a start is added |
notification_subscription[delete_enabled] |
Notify when a start is withdrawn |
notification_subscription[finished_enabled] |
Notify when a competition finishes |
notification_subscription[result_enabled] |
Notify when a result arrives |
curl -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"notification_subscription":{"target_identifier":"rider_820f70…","active":true,"result_enabled":true}}' \
https://online.equipe.com/api/v2/notification_subscriptions
Answers 200 with the created subscription, or 422 with a list of messages.
Changes which events a subscription notifies about, or turns it off. Takes the same fields as creating one. Returns no content.
curl -X PATCH -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"notification_subscription":{"result_enabled":false}}' \
https://online.equipe.com/api/v2/notification_subscriptions/1234
Stops following. Returns no content.
curl -X DELETE -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/notification_subscriptions/1234
Attachments
Uploading and removing files is for organizers and course designers. Reading the list is open to any account.
The files attached to a competition: course designs, start lists and other documents shown on the public schedule. Any account can read this list.
| Field | Description |
|---|---|
id |
Attachment id |
meeting_class_id |
The competition it belongs to |
name |
What the file is called |
contain |
What kind of file it is, when the name matched one of the attachment types: course_design, document, horse_list, logo, picture, portrait, result_list, rider_list or start_list |
description |
Free text, when there is one |
url |
Where the file is served from |
file_name / content_type / file_size |
The file itself: name, MIME type, size in bytes |
created_at |
When it was uploaded |
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/meeting_classes/1252772/attachments
[
{
"id": 88211,
"meeting_class_id": 1252772,
"name": "Course design",
"contain": "course_design",
"url": "https://online-uploads.equipeassets.com/assets/88211/original.pdf",
"file_name": "course_design.pdf",
"content_type": "application/pdf",
"file_size": 148733,
"created_at": "2026-08-02T14:11:53.000Z"
}
]
A show that has not been published yet answers 404, unless you have upload rights on it.
Uploads a file to a competition. Two kinds of account may do this: the show belongs to your organizer, or your account has the course designer role. A course designer may upload to any show, including one that has not been published yet. PDF, images and plain text, at most 10 MB. The file goes as multipart/form-data, not JSON.
| Parameter | Description |
|---|---|
attachment[file] |
The file itself |
attachment[name] |
What to call it. A name matching one of the attachment types files it as one — name it "Course design" and the schedule shows it as a course design. |
attachment[description] |
Free text shown with the file. Optional. |
curl -X POST -H "Authorization: Bearer $TOKEN" \
-F "attachment[name]=Course design" \
-F "attachment[file]=@course_design.pdf" \
https://online.equipe.com/api/v2/meeting_classes/1252772/attachments
{
"id": 88211,
"meeting_class_id": 1252772,
"name": "Course design",
"contain": "course_design",
"url": "https://online-uploads.equipeassets.com/assets/88211/original.pdf",
"file_name": "course_design.pdf",
"content_type": "application/pdf",
"file_size": 148733,
"created_at": "2026-08-02T14:11:53.000Z"
}
Answers 201 with the attachment, 403 {"error": "forbidden"} without upload rights, or 422 with a list of messages: a missing name, a file over 10 MB, or a type we do not accept. While uploads are paused for maintenance every upload answers 503.
Removes a file from a competition. Yours to remove when you uploaded it, or when the show belongs to your organizer. Note that this is narrower than uploading: a course designer cannot remove a file somebody else uploaded. Returns no content.
curl -X DELETE -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/attachments/88211
Account
The account the token belongs to. Ask for "me" when you do not know the id, which is the usual case. A numeric id works too, but only your own: the account that created the key, or the user who authorized your application.
| Parameter | Description |
|---|---|
id |
The account id, or "me" for whoever the token belongs to |
| Field | Description |
|---|---|
user.id |
Account id |
user.name |
Name |
user.email |
Email address |
user.roles |
admin, course_designer or organizer, when any apply |
user.organizer_id / organizer_name |
The organizer the account belongs to, when it does |
user.created_at / updated_at |
Timestamps |
curl -H "Authorization: Bearer $TOKEN" \
https://online.equipe.com/api/v2/users/me
{
"user": {
"id": 1,
"name": "Jon",
"email": "jon@example.com",
"roles": ["admin"],
"created_at": "2020-11-23T10:09:01.000Z",
"updated_at": "2026-07-22T16:58:50.000Z"
}
}
Any other id answers 404, whether that account exists or not. An OAuth client can also read the id from the OIDC sub claim, which is the same number.
Errors
| Status | Body | What happened |
|---|---|---|
| 401 | Access Denied… as plain text |
No token, or a token that has expired or been revoked. Note this one is text, not JSON. |
| 403 | {"error": "insufficient_scope", "required_scope": "write"} |
Your token is valid but lacks the scope the endpoint needs |
| 403 | {"error": "token_access_forbidden"} |
An endpoint no token may reach, whatever its scopes |
| 403 | {"error": "forbidden"} |
The record exists and you may see it, but this action on it is not yours to take |
| 404 | Empty | No such record, or one that is not yours |
| 422 | ["Target identifier can't be blank"] |
We understood the request and refused it. A list of sentences. |
What a token cannot do
Some things belong to the person, not to an integration. No access token reaches
them, however many scopes it has, and they answer
{"error": "token_access_forbidden"}:
- Signing in and signing out
- Changing an email address, which can merge two accounts
- Editing or creating an account
A key someone made for a cron job should not be able to take their account away from them, so it cannot.
Getting help
Email info@equipe.com and a person will answer. Tell us what you are building and what you tried — we would rather help early than read about it afterwards.
Changes to the API are announced at help.equipe.com.