Connect to Ordina: sign in for partner apps
Let owners connect your platform to their business with one click (OAuth 2.1 with PKCE), then call the API with the token you receive.
Connect to Ordina is how a platform gets access to a business without the owner copying an API key. The owner clicks your button, signs in to Ordina, sees what you are asking for, and approves. You receive a token for that one business.
- Register onceGet a client_id.
- Send the owner to OrdinaThey approve.
- Swap the codeFor tokens.
- Call the APIBearer ord_at_...
It is standard OAuth 2.1: the authorization code flow with PKCE (S256). Any OAuth library works.
| Authorization page | https://www.useordina.com/oauth/authorize |
| Token endpoint | https://www.useordina.com/api/oauth/token |
| Registration endpoint | https://www.useordina.com/api/oauth/register |
| Revocation endpoint | https://www.useordina.com/api/oauth/revoke |
| Discovery | https://www.useordina.com/.well-known/oauth-authorization-server |
| Scope | api |
1. Register your app, once
POST https://www.useordina.com/api/oauth/register
Content-Type: application/json
{
"client_name": "Your Platform",
"redirect_uris": ["https://yourplatform.com/ordina/callback"],
"token_endpoint_auth_method": "client_secret_post"
}
You get back a client_id, and a client_secret (shown once) when you chose client_secret_post or client_secret_basic. A browser or mobile app that cannot keep a secret registers with "none" and relies on PKCE alone. The client_name is what owners see on the approval page, so use your product's name. Up to 5 redirect URIs, https only (http is allowed for localhost while you develop).
2. Send the owner to Ordina
Make a PKCE verifier (43 to 128 random characters) and its S256 challenge, then redirect the owner:
https://www.useordina.com/oauth/authorize
?response_type=code
&client_id=ord_client_...
&redirect_uri=https://yourplatform.com/ordina/callback
&scope=api
&state=RANDOM_VALUE_YOU_CHECK_LATER
&code_challenge=BASE64URL_SHA256_OF_VERIFIER
&code_challenge_method=S256
The owner signs in if they need to, and sees what your app will be able to do:
- read their business details, appointments and orders;
- subscribe to webhooks;
- push knowledge to their Secretary;
- register connected actions, each off until they switch it on.
Only the owner can approve, and only on the Pro or Business plan.
They return to your redirect_uri with ?code=...&state=...&iss=https://www.useordina.com, or with ?error=access_denied if they said no. Check state matches what you sent.
3. Swap the code for tokens
POST https://www.useordina.com/api/oauth/token
Content-Type: application/x-www-form-urlencoded
grant_type=authorization_code
&code=ord_code_...
&redirect_uri=https://yourplatform.com/ordina/callback
&code_verifier=YOUR_VERIFIER
&client_id=ord_client_...
&client_secret=ord_cs_...
{ "access_token": "ord_at_...", "token_type": "Bearer", "expires_in": 3600, "refresh_token": "ord_rt_...", "scope": "api" }
A code works once and expires after 10 minutes.
4. Call the API
Send the access token exactly like an API key:
curl https://www.useordina.com/api/v1/me -H "Authorization: Bearer ord_at_..."
Every endpoint in the API reference accepts it. Call GET /api/v1/me first to learn which business you are connected to, and store the tokens against it.
5. Refresh before it expires
Access tokens last 1 hour; refresh tokens last 90 days and are rotated on every use:
POST https://www.useordina.com/api/oauth/token
grant_type=refresh_token&refresh_token=ord_rt_...&client_id=ord_client_...&client_secret=ord_cs_...
Store the new refresh token each time: an old one is refused. If a refresh fails with invalid_grant, the owner disconnected you or 90 days passed without use; send them through step 2 again.
Disconnecting
- The owner disconnects your app in Integration, Connected actions. Your tokens stop working at once. Actions and knowledge you added stay until the owner removes them.
- You can end the connection by posting either token to the revocation endpoint (
token=...&client_id=...).
What a token cannot do
A partner token reaches /api/v1 only. It cannot sign in to the dashboard, use the owner's AI assistant tools, change bookings, orders or payments, or switch an action on. If the business's plan lapses, calls return 403 until it is active again.
