OAuth API Schema
This reference covers the single OAuth 2.0 endpoint used to complete the authorization code flow. See the OAuth Flow guide for the full installation sequence, including how to initiate the authorization redirect and store the resulting token.
OAuth
Exchange an authorization code for a workspace-scoped access token.
POST /oauth2/token/exchange accepts the authorization code your app receives after an agent completes the CRM OAuth consent screen and returns an access_token tied to that workspace.
Base URL: The token exchange endpoint uses
https://api.askyura.com/api/, not the standardhttps://dev.askyura.com/api/prefix used by all other CRM endpoints.
Store one access token per workspace. Include it as a Bearer token on every subsequent API call:
Authorization: Bearer {access_token}There is no refresh token mechanism. If a token expires or is revoked, the agent must re-install the app to issue a new one.
Upsert Contact Custom Attributes PATCH
Creates or updates custom attributes for a contact. Keys must match existing custom attribute definitions in your workspace and are case-sensitive. Requires `contact:write` scope.
Exchange authorization code for access token POST
Exchange authorization code to access token