API documentation

Equipe Online API, version 2

Equipe Online publishes show schedules, start lists and results for equestrian competitions. This API is how you build on that: read the documents and results for the riders someone has given you access to, follow riders and horses, and be told when results arrive.

Everything lives under https://online.equipe.com. Requests and responses are JSON, and every request needs an access token. Getting one takes an application and a short review, because we want to know who is calling.

Getting started

The shortest path from nothing to a working request is a personal access token. It takes three steps.

  1. Apply for developer access at https://online.equipe.com/developer_application/new. Tell us what you are building and which company or person is behind it. We read every application and answer by email.
  2. Create a key once you are approved. Your developer page links to API keys; pick the scopes you need and copy the key. It is shown once and stored hashed, so if you lose it you create a new one.
  3. Call the API with the key as a bearer token.
bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/profiles

That returns the riders your account has been given access to. If the list is empty, connect a rider to your account first — the personal endpoints all follow from that list.

Two things to know before you build. The API is not for building something Equipe already offers. An app that competes with our own products will not be approved. And developer access is ours to give and ours to take back. We can withdraw it at any time, and when we do we will tell you why.

Back to top

Which authentication do I need

Two kinds of token reach the API, and the difference is whose data you are reading.

Personal access token OAuth application
Acts for Your own account Any Equipe user who authorizes you
How you get it You create it yourself The user is sent to Equipe and approves
Lifetime Until you revoke it 2 hours, then refreshed
Revoked by You The user, at any time
Good for A script, a cron job, your own integration A product other people sign in to

If you are collecting results for your own club, take a personal access token. If you are building something riders log in to, you want OAuth.

Back to top

Personal access tokens

A personal access token is a key you make for yourself. It carries your own access: the riders connected to your account, your documents, your notifications. Treat it like a password, because it is one.

  • Choose read, write or both when you create it. Nothing else.
  • It does not expire. It stops working when you revoke it, and not before.
  • There is no refresh token, because there is nothing to refresh.
  • We show it once. We keep a hash, so we cannot show it to you again and neither can anyone who reads our database.
  • Revoking one takes effect on the next request.

Give each integration its own key. Then revoking the one that leaked does not stop everything else you run.

Back to top

OAuth 2.0

Use OAuth when your product acts for other Equipe users. They stay in control: they see what you are asking for, they approve it, and they can take it back.

We support the authorization code flow. There is no implicit flow, no password grant and no client credentials grant.

Applications are confidential, and we send no CORS headers. The token exchange uses your client secret, so it has to happen on your server. A browser-only client cannot complete it.

Register an application

Approved developers register applications on their developer page. You give the name and description people see when they authorize you, a website and privacy policy, a support address, and one redirect URI per line. You get a client id and a client secret; the secret is shown once.

Send the user to Equipe

GET https://online.equipe.com/oauth/authorize
  ?client_id=YOUR_CLIENT_ID
  &redirect_uri=https://example.com/callback
  &response_type=code
  &scope=read
  &state=RANDOM_STRING
ParameterDescription
client_idFrom your registered application. Required.
redirect_uriMust match one you registered, exactly. Required.
response_typecode. Required.
scopeSpace separated. Defaults to read.
stateReturned to you unchanged. Use it, and check it.
code_challengePKCE, see below.
code_challenge_methodS256 or plain.

If they are not signed in we ask them to, and bring them back. Then they see who is asking, what you say your application does, links to your site and privacy policy, and the list of things you want to be allowed to do. Denying sends them back to your redirect URI with error=access_denied.

Exchange the code

Approving sends them to your redirect URI with ?code=…&state=…. The code is good for ten minutes and once.

bash
curl -X POST https://online.equipe.com/oauth/token \
  -d grant_type=authorization_code \
  -d code=RETURNED_CODE \
  -d redirect_uri=https://example.com/callback \
  -d client_id=YOUR_CLIENT_ID \
  -d client_secret=YOUR_CLIENT_SECRET
{
  "access_token": "…",
  "token_type": "Bearer",
  "expires_in": 7200,
  "refresh_token": "…",
  "scope": "read",
  "created_at": 1786042773
}

Refresh, and the one rule about it

Access tokens last 2 hours. Trade the refresh token for a new pair before or after it runs out — the user is not involved.

bash
curl -X POST https://online.equipe.com/oauth/token \
  -d grant_type=refresh_token \
  -d refresh_token=YOUR_REFRESH_TOKEN \
  -d client_id=YOUR_CLIENT_ID \
  -d client_secret=YOUR_CLIENT_SECRET

Refresh tokens rotate. Every refresh gives you a new refresh token and retires the old one as soon as the new access token is used. Store the new one and forget the old. If an old refresh token turns up again we treat it as a copy and reject the exchange, which means a client that retries with a stale token loses the whole chain and has to ask the user again.

PKCE

We accept S256 and plain. It is not required, and we recommend it anyway: send code_challenge and code_challenge_method with the authorize request, and code_verifier with the exchange.

Giving a token back

bash
curl -X POST https://online.equipe.com/oauth/revoke \
  -d token=THE_TOKEN \
  -d client_id=YOUR_CLIENT_ID \
  -d client_secret=YOUR_CLIENT_SECRET

POST /oauth/introspect tells you whether a token is still good, and GET /oauth/token/info describes the token you are holding. Users manage what they have authorized from their own account page, and revoking there stops your access immediately.

Back to top

Sign in with Equipe

On top of OAuth we speak OpenID Connect, so people can sign in to your product with their Equipe account. Any standard OIDC library will do the work if you point it at our discovery document.

https://online.equipe.com/.well-known/openid-configuration

That document is the authority. If anything here disagrees with it, believe the document.

  • Issuer: https://online.equipe.com
  • Public keys: https://online.equipe.com/oauth/discovery/keys
  • User info: https://online.equipe.com/oauth/userinfo

Ask for the openid scope, plus profile and email for the claims you need. You can ask for read or write in the same breath, and the consent screen lists all of it together.

ClaimScopeWhat it is
subopenidThe account id, as a string. Stable. Key your users on it.
nameprofileThe name on the account
emailemailThe email address
email_verifiedemailAlways true: signing in to Equipe means receiving a code at that address

The claims are in the id_token and at the user info endpoint alike.

bash
curl -H "Authorization: Bearer $ACCESS_TOKEN" \
  https://online.equipe.com/oauth/userinfo
{
  "sub": "1",
  "name": "Jon Stenqvist",
  "email": "jon@example.com",
  "email_verified": true
}

Back to top

Scopes

A token carries scopes, and scopes decide what it may do. These are the words the user sees when they authorize your application.

ScopeWhat the user is asked to allow
read Read your results, documents and schedules
write Follow riders, manage notifications and upload files on your behalf
openid Know who you are on Equipe
profile See your name
email See your email address

read and write reach the API. openid, profile and email are about identity and are only useful for signing in. An application may only ask for scopes from this list.

Read and write are separate, not a ladder. A token with only write is refused by the endpoints that need read, exactly as the other way round. Most integrations want both.

Back to top

Making requests

Send the token on every request:

Authorization: Bearer YOUR_TOKEN

Send Content-Type: application/json when you have a body, and nest the body under the name of the thing you are working with: {"notification_subscription": {"active": true}}, not {"active": true}.

Timestamps are ISO 8601 in UTC.

Blank values are left out. Most responses drop keys whose value is null, false or empty rather than sending them. A notification that has not been read has no read key at all, so read the absence of a key as its blank value. The rider list is the one exception: it keeps its zeros and its false, because a follower count of zero is an answer.

Only /api/v2/documents is paged, with offset. Everything else returns what it has.

We do not send CORS headers, so call us from your server rather than from a browser. There is no published rate limit; use the API at a rate you would be comfortable explaining, and cache what you can.

Back to top

Endpoint reference

EndpointScope
GET /api/v2/profiles read Details
GET /api/v2/documents read Details
GET /api/v2/results read Details
GET /api/v2/profiles/:profile_id/results read Details
GET /api/v2/starts/:start_id/score_sheets read Details
GET /api/v2/push_messages read Details
PUT /api/v2/push_messages/read_all write Details
DELETE /api/v2/push_messages/:id write Details
DELETE /api/v2/push_messages write Details
GET /api/v2/notification_subscriptions read Details
GET /api/v2/targets/:target_identifier/notification_subscriptions read Details
POST /api/v2/notification_subscriptions write Details
PATCH /api/v2/notification_subscriptions/:id write Details
DELETE /api/v2/notification_subscriptions/:id write Details
GET /api/v2/meeting_classes/:meeting_class_id/attachments read Details
POST /api/v2/meeting_classes/:meeting_class_id/attachments write Details
DELETE /api/v2/attachments/:id write Details
GET /api/v2/users/:id read Details

Riders

GET /api/v2/profiles read

The riders the account has been given access to. This is the list every other personal endpoint is scoped by: documents and notifications follow from it.

FieldDescription
id Equipe Online id for the rider profile
name Rider name
target_identifier The identifier used to follow this rider elsewhere in the API
identifier_key Where the rider was identified: fei, licence, email or id
identifier_id The identifier itself, for example an FEI id
birth_year Year of birth, when known
age Age in whole years, when the birth year is known
logo_id / logo_group Portrait reference
private_notifications Whether followers need the rider to approve them
approved_followers_count Followers receiving notifications, approved either way
user_approved_followers_count Followers the rider approved by hand
auto_approved_followers_count Followers approved automatically on a public profile
pending_followers_count Follow requests waiting for the rider
bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/profiles
[
  {
    "id": 42,
    "name": "Jessie Stenqvist",
    "target_identifier": "rider_820f70fbf096631173bc380f515a0ad0",
    "identifier_key": "svrf",
    "identifier_id": "17860",
    "birth_year": null,
    "age": null,
    "logo_id": "802",
    "logo_group": "svrf",
    "private_notifications": true,
    "approved_followers_count": 21,
    "user_approved_followers_count": 0,
    "auto_approved_followers_count": 21,
    "pending_followers_count": 2
  }
]

Documents

GET /api/v2/documents read

Result lists, invoices and other documents for the riders the account has access to, newest first.

ParameterDescription
offset Skip this many documents. 50 are returned per request.
FieldDescription
id Document id
label What the document is called
pdf_logo_identifier Reference used to fetch the PDF itself
created_at When the document was produced
meeting_id / meeting_name The show it belongs to
meeting_class_name The competition, when the document belongs to one
class_section_id A start list in that competition, when there is one
rider_name The rider the document is about
bash
curl -H "Authorization: Bearer $TOKEN" \
  "https://online.equipe.com/api/v2/documents?offset=50"
[
  {
    "id": 9182,
    "label": "Result list",
    "pdf_logo_identifier": "8fa1c0…",
    "created_at": "2026-08-02T14:11:53.000Z",
    "meeting_id": 68000,
    "meeting_name": "Falsterbo Horse Show",
    "meeting_class_name": "145 cm Two phases",
    "class_section_id": 551202,
    "rider_name": "Jessie Stenqvist"
  }
]

Results

GET /api/v2/results read

Every start for the riders the account has access to, newest first. A start is here as soon as the start list is published, and the placing and result arrive with the result.

ParameterDescription
offset Skip this many starts. 25 are returned per request.
FieldDescription
id Start id
class_section_id The start list this start is in
rank Placing, when the competition has been ranked
result_preview The result as the start list shows it: points, faults or a time
meeting_class_start_at When the competition started
meeting_name The show
meeting_class_name The competition
rider_name / horse_name / club_name Who rode what, for whom
venue_country Country the show was held in
discipline Discipline code, for example D for dressage or H for show jumping
logo_id / logo_group Organizer logo reference
rider_notification_identifier / horse_notification_identifier The identifiers used to follow this rider and horse elsewhere in the API
bash
curl -H "Authorization: Bearer $TOKEN" \
  "https://online.equipe.com/api/v2/results?offset=25"
[
  {
    "id": 21485922,
    "class_section_id": 1283367,
    "rank": 1,
    "result_preview": "68.723",
    "meeting_class_start_at": "2026-08-16T11:34:00.000Z",
    "meeting_name": "Ödåkra Ridsällskap",
    "meeting_class_name": "Medelsvår B:5",
    "rider_name": "Jessie Stenqvist",
    "horse_name": "Red Zolo (SWB)",
    "club_name": "Helsingborgs Fältrittklubb",
    "venue_country": "SWE",
    "discipline": "D",
    "logo_id": "235",
    "logo_group": "svrf",
    "rider_notification_identifier": "rider_820f70fbf096631173bc380f515a0ad0",
    "horse_notification_identifier": "horse_84a945663f765b9156b0104937cd1762"
  }
]

class_section_id takes you to the start list, and the start id is the anchor on it: https://online.equipe.com/startlists/1283367#start_21485922 opens the list at that start.

GET /api/v2/profiles/:profile_id/results read

The same list for one rider. The id is the one from the profiles list, and it has to be a rider your account has access to. Any other id returns nothing.

ParameterDescription
offset Skip this many starts. 25 are returned per request.
bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/profiles/42/results
GET /api/v2/starts/:start_id/score_sheets read

The judged protocols of one start: every movement on the sheet with each judge's mark against it, the judges with what they each arrived at, and the result the protocol produced. Dressage and working equitation have protocols. Any other start, and one that has not been judged yet, answers with an empty list. The start has to be ridden by a rider your account has access to; any other id answers 404.

FieldDescription
marking_sheet_id Identifies the protocol within the competition
name / description What the protocol is called, and its edition, arena and maximum
sheet_type A letter classifying the sheet: D is a dressage test, K a freestyle, W a working equitation test. Other letters occur.
max_score The most points the sheet can give
total / percent / rank The result of this protocol: for dressage the final result across the judges, for working equitation the result of that test. Percent is a string, formatted the way the result list shows it. total is the points added up, which dressage publishes and working equitation does not.
judges[] judge_by is the position (C, E, H, M or B); alias is what the sheet calls that position. name and country come from the start list.
judges[].total / percent / rank / deduction What that judge arrived at, when the discipline scores per judge. Working equitation scores the test, not each judge, so they are null there.
judges[].technical_percent / artistic_percent Freestyle only
items[] The rows of the sheet in order: position, group_no, section, keyword, place, instruction, coefficient, scale
items[].section Which part of the sheet the row belongs to. technical is the movements, artistic the collective marks, and a section ending in _deduction is a deduction row.
items[].points The mark from each judge, keyed by judge_by. Empty on a row nobody marks, such as the deduction row.
items[].exclude_max_score True on a row that does not count towards max_score
bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/starts/21485922/score_sheets
[
  {
    "marking_sheet_id": "10145",
    "name": "Medelsvår B:5",
    "description": "Edition 2024, arena 20x60, max 470 points, time approx. 5.5 min",
    "sheet_type": "D",
    "max_score": 470.0,
    "total": 296.0,
    "percent": "62.979",
    "rank": 3,
    "judges": [
      {
        "judge_by": "C",
        "alias": "C",
        "name": "Annica Wiberg",
        "country": "SWE",
        "total": 296.0,
        "percent": "62.979",
        "technical_percent": null,
        "artistic_percent": null,
        "rank": 3,
        "deduction": 0.0
      }
    ],
    "items": [
      {
        "position": 0,
        "group_no": "1",
        "section": "technical",
        "keyword": "Inridning",
        "place": "AX\nX\nXC",
        "instruction": "Inridning i samlad galopp\nHalt - hälsning\nSamlad trav",
        "coefficient": 1.0,
        "scale": 10,
        "exclude_max_score": false,
        "points": { "C": 7 }
      },
      {
        "position": 30,
        "group_no": "3",
        "section": "artistic",
        "keyword": "Lösgjordhet",
        "place": null,
        "instruction": "Lösgjordhet (eftergift på tygeln, formen, accepterande av bettet…)",
        "coefficient": 2.0,
        "scale": 10,
        "exclude_max_score": false,
        "points": { "C": 6 }
      },
      {
        "position": 32,
        "group_no": null,
        "section": "technical_deduction",
        "keyword": "Poängavdrag",
        "place": null,
        "instruction": "Felridning första gången 2p - Felridning andra gången 4p",
        "coefficient": 1.0,
        "scale": 10,
        "exclude_max_score": true,
        "points": {}
      }
    ]
  }
]

A start usually has one protocol. Working equitation publishes one per judged test, in riding order. Every key is always present, null where the protocol has nothing to say.

Notifications

GET /api/v2/push_messages read

The 25 most recent notifications for the account, newest first. The response supports ETag and Last-Modified, so a conditional request costs you a 304.

FieldDescription
push_messages[] id, alert, event, subject_id, subject_type, meeting_id, meeting_name, class_section_id, logo_id, logo_group, created_at, updated_at
push_messages[].read Present and true once the notification has been read
push_messages[].read_at When it was read
push_notification The account's notification record: id, unread_count, timestamps
bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/push_messages
{
  "push_messages": [
    {
      "id": 771,
      "alert": "Jessie Stenqvist is next to go in 145 cm Two phases",
      "event": "start",
      "meeting_id": 68000,
      "meeting_name": "Falsterbo Horse Show",
      "class_section_id": 551202,
      "created_at": "2026-08-02T14:09:00.000Z"
    }
  ],
  "push_notification": { "id": 12, "unread_count": 1 }
}
PUT /api/v2/push_messages/read_all write

Marks every unread notification as read. Returns no content.

bash
curl -X PUT -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/push_messages/read_all
DELETE /api/v2/push_messages/:id write

Removes one notification. Returns no content.

bash
curl -X DELETE -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/push_messages/771
DELETE /api/v2/push_messages write

Removes every notification for the account. Returns no content.

bash
curl -X DELETE -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/push_messages

Following riders and horses

GET /api/v2/notification_subscriptions read

Everything the account follows.

ParameterDescription
target_identifier Only the subscription for this rider or horse
FieldDescription
notification_subscriptions[] id, target_identifier, title, subtitle, logo_url, status, timestamps
notification_subscriptions[].active Present and true while the subscription is on
notification_subscriptions[].status pending, auto_approved, user_approved, auto_rejected or user_rejected
profile Only when target_identifier was given: the rider's name and whether the profile is private
bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/notification_subscriptions
GET /api/v2/targets/:target_identifier/notification_subscriptions read

The same list narrowed to one rider or horse, with the identifier in the path instead of the query string.

bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/targets/rider_820f70…/notification_subscriptions
POST /api/v2/notification_subscriptions write

Starts following a rider or horse. On a private profile the subscription is created as pending and the rider decides; on a public one it is approved immediately.

ParameterDescription
notification_subscription[target_identifier] The rider or horse to follow. Required.
notification_subscription[active] Whether the subscription is on
notification_subscription[reason] Shown to the rider with a request on a private profile
notification_subscription[create_enabled] Notify when a start is added
notification_subscription[delete_enabled] Notify when a start is withdrawn
notification_subscription[finished_enabled] Notify when a competition finishes
notification_subscription[result_enabled] Notify when a result arrives
bash
curl -X POST -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"notification_subscription":{"target_identifier":"rider_820f70…","active":true,"result_enabled":true}}' \
  https://online.equipe.com/api/v2/notification_subscriptions

Answers 200 with the created subscription, or 422 with a list of messages.

PATCH /api/v2/notification_subscriptions/:id write

Changes which events a subscription notifies about, or turns it off. Takes the same fields as creating one. Returns no content.

bash
curl -X PATCH -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"notification_subscription":{"result_enabled":false}}' \
  https://online.equipe.com/api/v2/notification_subscriptions/1234
DELETE /api/v2/notification_subscriptions/:id write

Stops following. Returns no content.

bash
curl -X DELETE -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/notification_subscriptions/1234

Attachments

Uploading and removing files is for organizers and course designers. Reading the list is open to any account.

GET /api/v2/meeting_classes/:meeting_class_id/attachments read

The files attached to a competition: course designs, start lists and other documents shown on the public schedule. Any account can read this list.

FieldDescription
id Attachment id
meeting_class_id The competition it belongs to
name What the file is called
contain What kind of file it is, when the name matched one of the attachment types: course_design, document, horse_list, logo, picture, portrait, result_list, rider_list or start_list
description Free text, when there is one
url Where the file is served from
file_name / content_type / file_size The file itself: name, MIME type, size in bytes
created_at When it was uploaded
bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/meeting_classes/1252772/attachments
[
  {
    "id": 88211,
    "meeting_class_id": 1252772,
    "name": "Course design",
    "contain": "course_design",
    "url": "https://online-uploads.equipeassets.com/assets/88211/original.pdf",
    "file_name": "course_design.pdf",
    "content_type": "application/pdf",
    "file_size": 148733,
    "created_at": "2026-08-02T14:11:53.000Z"
  }
]

A show that has not been published yet answers 404, unless you have upload rights on it.

POST /api/v2/meeting_classes/:meeting_class_id/attachments write

Uploads a file to a competition. Two kinds of account may do this: the show belongs to your organizer, or your account has the course designer role. A course designer may upload to any show, including one that has not been published yet. PDF, images and plain text, at most 10 MB. The file goes as multipart/form-data, not JSON.

ParameterDescription
attachment[file] The file itself
attachment[name] What to call it. A name matching one of the attachment types files it as one — name it "Course design" and the schedule shows it as a course design.
attachment[description] Free text shown with the file. Optional.
bash
curl -X POST -H "Authorization: Bearer $TOKEN" \
  -F "attachment[name]=Course design" \
  -F "attachment[file]=@course_design.pdf" \
  https://online.equipe.com/api/v2/meeting_classes/1252772/attachments
{
  "id": 88211,
  "meeting_class_id": 1252772,
  "name": "Course design",
  "contain": "course_design",
  "url": "https://online-uploads.equipeassets.com/assets/88211/original.pdf",
  "file_name": "course_design.pdf",
  "content_type": "application/pdf",
  "file_size": 148733,
  "created_at": "2026-08-02T14:11:53.000Z"
}

Answers 201 with the attachment, 403 {"error": "forbidden"} without upload rights, or 422 with a list of messages: a missing name, a file over 10 MB, or a type we do not accept. While uploads are paused for maintenance every upload answers 503.

DELETE /api/v2/attachments/:id write

Removes a file from a competition. Yours to remove when you uploaded it, or when the show belongs to your organizer. Note that this is narrower than uploading: a course designer cannot remove a file somebody else uploaded. Returns no content.

bash
curl -X DELETE -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/attachments/88211

Account

GET /api/v2/users/:id read

The account the token belongs to. Ask for "me" when you do not know the id, which is the usual case. A numeric id works too, but only your own: the account that created the key, or the user who authorized your application.

ParameterDescription
id The account id, or "me" for whoever the token belongs to
FieldDescription
user.id Account id
user.name Name
user.email Email address
user.roles admin, course_designer or organizer, when any apply
user.organizer_id / organizer_name The organizer the account belongs to, when it does
user.created_at / updated_at Timestamps
bash
curl -H "Authorization: Bearer $TOKEN" \
  https://online.equipe.com/api/v2/users/me
{
  "user": {
    "id": 1,
    "name": "Jon",
    "email": "jon@example.com",
    "roles": ["admin"],
    "created_at": "2020-11-23T10:09:01.000Z",
    "updated_at": "2026-07-22T16:58:50.000Z"
  }
}

Any other id answers 404, whether that account exists or not. An OAuth client can also read the id from the OIDC sub claim, which is the same number.

Back to top

Errors

StatusBodyWhat happened
401 Access Denied… as plain text No token, or a token that has expired or been revoked. Note this one is text, not JSON.
403 {"error": "insufficient_scope", "required_scope": "write"} Your token is valid but lacks the scope the endpoint needs
403 {"error": "token_access_forbidden"} An endpoint no token may reach, whatever its scopes
403 {"error": "forbidden"} The record exists and you may see it, but this action on it is not yours to take
404 Empty No such record, or one that is not yours
422 ["Target identifier can't be blank"] We understood the request and refused it. A list of sentences.

Back to top

What a token cannot do

Some things belong to the person, not to an integration. No access token reaches them, however many scopes it has, and they answer {"error": "token_access_forbidden"}:

  • Signing in and signing out
  • Changing an email address, which can merge two accounts
  • Editing or creating an account

A key someone made for a cron job should not be able to take their account away from them, so it cannot.

Back to top

Getting help

Email info@equipe.com and a person will answer. Tell us what you are building and what you tried — we would rather help early than read about it afterwards.

Changes to the API are announced at help.equipe.com.

Back to top