Authentication
Tikk supports two kinds of credentials. Both are sent the same way, as a Bearer token, and both are limited by scopes.
| Credential | Use it for |
|---|---|
| OAuth access token | Integrations used by many Tikk users. This is what partners use. |
API key (tikk_sk_…) |
A Tikk user scripting against their own account. Created in Tikk under Settings → API keys. |
The rest of this page covers OAuth.
1. Redirect the user to Tikk
Send the user's browser to the authorize endpoint:
https://app.tikk.chat/oauth/authorize
?client_id=YOUR_CLIENT_ID
&redirect_uri=https://your-app.example/callback
&response_type=code
&scope=profile.read availability.read
&state=RANDOM_STRING
| Parameter | Required | Notes |
|---|---|---|
client_id |
yes | From your app's page in My apps. |
redirect_uri |
yes | Must exactly match one of your app's redirect URIs. |
response_type |
yes | Always code. |
scope |
no | Space-separated. Defaults to profile.read. Scopes your app is not allowed to use are dropped. |
state |
recommended | A random value you check on the way back, to protect against CSRF. |
The user signs in to Tikk (if needed), sees your app's name, your company name and the requested permissions, and approves or denies.
2. Handle the callback
On approval, Tikk redirects to your redirect_uri:
https://your-app.example/callback?code=AUTHORIZATION_CODE&state=RANDOM_STRING
If the user denies, you receive error=access_denied instead. Always check that state matches what you sent.
3. Exchange the code for tokens
Make a server-side POST to the token endpoint. Never do this from the browser, because it needs your client secret.
curl -X POST https://app.tikk.chat/oauth/token \
-H "Accept: application/json" \
-d grant_type=authorization_code \
-d client_id=YOUR_CLIENT_ID \
-d client_secret=YOUR_CLIENT_SECRET \
-d redirect_uri=https://your-app.example/callback \
-d code=AUTHORIZATION_CODE
Response:
{
"token_type": "Bearer",
"expires_in": 2592000,
"access_token": "eyJ0eXAiOiJKV1Qi...",
"refresh_token": "def50200..."
}
Store both tokens per Tikk user.
4. Refresh the access token
Access tokens last 30 days; refresh tokens last 90 days. Before the access token expires, trade the refresh token for a new pair:
curl -X POST https://app.tikk.chat/oauth/token \
-H "Accept: application/json" \
-d grant_type=refresh_token \
-d refresh_token=REFRESH_TOKEN \
-d client_id=YOUR_CLIENT_ID \
-d client_secret=YOUR_CLIENT_SECRET
Each refresh returns a new refresh token; the old one stops working. If refreshing fails (the user disconnected your app, or the refresh token expired), send the user through the authorize flow again.
Disconnecting
Users can disconnect your app at any time in Tikk under Settings → Connected apps. Their tokens then return 401 and you should show them as disconnected.
Keeping your secret safe
Your client secret is shown once, when you create the app or regenerate the secret. If it leaks, regenerate it on the app's page: the old secret stops working immediately, but existing user tokens keep working.