openapi: 3.0.3 info: title: MemberClicks MC Professional Attributes Authorization API description: 'The MemberClicks MC Professional API (formerly branded "Oasis") is a JSON REST API for interacting with an organization''s association / membership management data - profiles, attributes, member types and statuses, groups, events, and continuing education credits. MemberClicks is owned by Personify. The API is protected by the OAuth 2.0 authorization framework: a client obtains an access token from /oauth/v1/token using HTTP Basic client credentials (Base64 clientId:clientSecret) with scope "read", "write", or "read write", then sends it as an Authorization: Bearer token on each request along with an Accept: application/json header. The API is hosted per organization at https://{orgId}.memberclicks.net, where {orgId} is the organization''s MC Professional ID. There is no single global host and no open self-serve key issuance - client credentials are provisioned inside an MC Professional account under API Management. MemberClicks notes the API is intended for developers with technical expertise and that support does not assist with custom integrations. Endpoints for Countries, Groups, and Events are documented as API resources but their exact paths are behind gated (Cloudflare-protected) developer documentation; those paths in this document are modeled to the confirmed /api/v1/{resource} convention (see x-endpoint-status).' version: '1.0' contact: name: MemberClicks by Personify url: https://memberclicks.com servers: - url: https://{orgId}.memberclicks.net description: Per-organization MC Professional host variables: orgId: default: your-org description: The organization's MC Professional ID. security: - oauth2: [] tags: - name: Authorization description: OAuth 2.0 token issuance. paths: /oauth/v1/token: post: operationId: createAccessToken tags: - Authorization summary: Obtain an OAuth 2.0 access token description: Exchanges client credentials for an access token. The client ID and secret are Base64-encoded as clientId:clientSecret in an HTTP Basic Authorization header. Request scope "read", "write", or "read write". security: [] parameters: - name: Authorization in: header required: true schema: type: string description: Basic requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object properties: grant_type: type: string example: client_credentials scope: type: string example: read write responses: '200': description: An access token. content: application/json: schema: type: object properties: access_token: type: string token_type: type: string example: bearer expires_in: type: integer scope: type: string '401': $ref: '#/components/responses/Unauthorized' components: responses: Unauthorized: description: Missing or invalid access token. content: application/json: schema: $ref: '#/components/schemas/Error' schemas: Error: type: object properties: error: type: string message: type: string securitySchemes: oauth2: type: oauth2 description: OAuth 2.0. Obtain a bearer token from /oauth/v1/token using HTTP Basic client credentials (Base64 clientId:clientSecret) with scope read, write, or read write. flows: clientCredentials: tokenUrl: https://{orgId}.memberclicks.net/oauth/v1/token scopes: read: Read access to resources. write: Write access to resources.