openapi: 3.2.0 info: title: OFX AISP Authorization Code API version: '2026-09-22' description: 'GENERATED FROM DOCUMENTATION by API Evangelist on 2026-09-22: 8 operation(s) read from 6 public documentation page(s) (each operation names its page in x-source). This is not the provider''s published contract; OFX has published no machine-readable contract that the pipeline could find. Engine: local.' x-generated-from: documentation x-provenance: generated x-authored-by: API Evangelist x-generated: '2026-09-22' x-generator: generate-contract-from-docs.py x-engine: local x-sources: - https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTI0-post-token - https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTI1-get-authorize - https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTIy-post-refresh-token - https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTIz-post-authorization-code - https://api-docs.ofx.com/docs/aisp-api/b3A6Mzc1NDY5NTg-create-account-access-consents - https://api-docs.ofx.com/docs/aisp-api/b3A6Mzc1NDY5NjE-get-accounts x-docs-section: aisp-api servers: - url: https://beta.api.ofx.com security: - OAuth_2.0: - payments tags: - name: Authorization Code paths: /authorization_code: post: operationId: post_authorization_code tags: - Authorization Code summary: The endpoint to issue the token x-source: https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTIz-post-authorization-code parameters: - name: grant_type in: query required: true schema: type: string description: response type. must be authorization_code. - name: client_id in: query required: true schema: type: string description: client identifier - name: client_secret in: query required: true schema: type: string description: client secret - name: scope in: query required: true schema: type: string description: the scope of the access request - name: code in: query required: true schema: type: string description: authorization code - name: state in: query required: false schema: type: string description: optional state to be sent back to callback url - name: redirect_uri in: query required: true schema: type: string description: authorization code flow callback url responses: '200': description: Success (status as documented) content: application/json: schema: $ref: '#/components/schemas/PostAuthorizationCodeResponse' components: schemas: PostAuthorizationCodeResponse: type: object properties: Location: type: string description: User will get a token securitySchemes: OAuth_2.0: type: oauth2 flows: clientCredentials: tokenUrl: https://sandbox.api.ofx.com/v1/oauth/token scopes: payments: '' authorizationCode: authorizationUrl: https://sandbox.api.ofx.com/v1/oauth/authorize tokenUrl: https://sandbox.api.ofx.com/v1/oauth/token scopes: payments: '' x-source: https://api-docs.ofx.com/docs/aisp-api/ZG9jOjExNjE2NDU1-authentication