openapi: 3.2.0 info: title: OFX AISP OAuth API version: '2026-09-22' description: 'GENERATED FROM DOCUMENTATION by API Evangelist on 2026-09-22: 8 operation(s) read from 6 public documentation page(s) (each operation names its page in x-source). This is not the provider''s published contract; OFX has published no machine-readable contract that the pipeline could find. Engine: local.' x-generated-from: documentation x-provenance: generated x-authored-by: API Evangelist x-generated: '2026-09-22' x-generator: generate-contract-from-docs.py x-engine: local x-sources: - https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTI0-post-token - https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTI1-get-authorize - https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTIy-post-refresh-token - https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTIz-post-authorization-code - https://api-docs.ofx.com/docs/aisp-api/b3A6Mzc1NDY5NTg-create-account-access-consents - https://api-docs.ofx.com/docs/aisp-api/b3A6Mzc1NDY5NjE-get-accounts x-docs-section: aisp-api servers: - url: https://beta.api.ofx.com security: - OAuth_2.0: - payments tags: - name: OAuth paths: /v1/oauth/authorize: get: operationId: get_v1_oauth_authorize tags: - OAuth summary: The endpoint to log the user in and issue the authorize code x-source: https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTI1-get-authorize parameters: - name: client_id in: query required: true schema: type: string - name: consent_id in: query required: true schema: type: string - name: redirect_uri in: query required: true schema: type: string - name: response_type in: query required: true schema: type: string - name: scope in: query required: true schema: type: string - name: state in: query required: false schema: type: string responses: '200': description: Success (status as documented) /v1/oauth/token: post: operationId: post_v1_oauth_token tags: - OAuth summary: The endpoint to issue the access token x-source: https://api-docs.ofx.com/docs/aisp-api/ZG9jOjM3NTQ2OTI0-post-token requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PostV1OauthTokenRequest' responses: '200': description: Success (status as documented) content: application/json: schema: $ref: '#/components/schemas/PostV1OauthTokenResponse' components: schemas: PostV1OauthTokenRequest: type: object properties: client_id: type: string description: client identifier client_secret: type: string description: client secret password grant_type: type: string description: authorization grant flow. can be client_credentials or authorization_code or refresh_token scope: type: string description: the scope of the access request required: - client_id - client_secret - grant_type - scope PostV1OauthTokenResponse: type: object properties: access_token: type: string expires_in: type: integer refresh_token: type: string refresh_token_expires_in: type: integer token_type: type: string securitySchemes: OAuth_2.0: type: oauth2 flows: clientCredentials: tokenUrl: https://sandbox.api.ofx.com/v1/oauth/token scopes: payments: '' authorizationCode: authorizationUrl: https://sandbox.api.ofx.com/v1/oauth/authorize tokenUrl: https://sandbox.api.ofx.com/v1/oauth/token scopes: payments: '' x-source: https://api-docs.ofx.com/docs/aisp-api/ZG9jOjExNjE2NDU1-authentication