[{"data":1,"prerenderedAt":1239},["ShallowReactive",2],{"navigation":3,"\u002Fapi\u002Flong-term-access":235},[4,10,120,130,153,175,207,211,215,220,225],{"title":5,"path":6,"stem":7,"icon":8,"excluded":9},"Introduction","\u002F","1.index",null,false,{"title":11,"path":12,"stem":13,"children":14,"icon":119,"excluded":9},"Application","\u002Fapplication","2.application\u002F1.index",[15,18,46,69],{"title":16,"path":12,"stem":13,"icon":17,"excluded":9},"Overview","lucide:compass",{"title":19,"path":20,"stem":21,"children":22,"icon":25,"excluded":9},"Stock","\u002Fapplication\u002Fstock","2.application\u002F2.stock\u002F1.index",[23,26,31,36,41],{"title":24,"path":20,"stem":21,"icon":25,"excluded":9},"Stock page overview","lucide:warehouse",{"title":27,"path":28,"stem":29,"icon":30,"excluded":9},"Managing your stock","\u002Fapplication\u002Fstock\u002Fmanaging-stock","2.application\u002F2.stock\u002F2.managing-stock","lucide:package",{"title":32,"path":33,"stem":34,"icon":35,"excluded":9},"Starting a change","\u002Fapplication\u002Fstock\u002Fstarting-a-change","2.application\u002F2.stock\u002F3.starting-a-change","lucide:refresh-cw",{"title":37,"path":38,"stem":39,"icon":40,"excluded":9},"Multiple stocks & customization","\u002Fapplication\u002Fstock\u002Fmultiple-stocks","2.application\u002F2.stock\u002F4.multiple-stocks","lucide:layout-grid",{"title":42,"path":43,"stem":44,"icon":45,"excluded":9},"Header counters","\u002Fapplication\u002Fstock\u002Fheader-counters","2.application\u002F2.stock\u002F5.header-counters","lucide:sliders-horizontal",{"title":47,"path":48,"stem":49,"children":50,"icon":53,"excluded":9},"Catalog","\u002Fapplication\u002Fcatalog","2.application\u002F3.catalog\u002F1.index",[51,54,59,64],{"title":52,"path":48,"stem":49,"icon":53,"excluded":9},"Catalog & type details","lucide:book-open",{"title":55,"path":56,"stem":57,"icon":58,"excluded":9},"Custom types","\u002Fapplication\u002Fcatalog\u002Fcustom-types","2.application\u002F3.catalog\u002F2.custom-types","lucide:plus-circle",{"title":60,"path":61,"stem":62,"icon":63,"excluded":9},"Proposing a type for the official catalog","\u002Fapplication\u002Fcatalog\u002Fproposing-to-catalog","2.application\u002F3.catalog\u002F3.proposing-to-catalog","lucide:badge-check",{"title":65,"path":66,"stem":67,"icon":68,"excluded":9},"Ratings, personalization & custom fields","\u002Fapplication\u002Fcatalog\u002Fratings-and-personalization","2.application\u002F3.catalog\u002F4.ratings-and-personalization","lucide:star",{"title":70,"path":71,"stem":72,"children":73,"icon":75,"excluded":9},"Settings","\u002Fapplication\u002Fsettings","2.application\u002F5.settings\u002F1.index",[74,76,81,86,91,96,100,104,109,114],{"title":70,"path":71,"stem":72,"icon":75,"excluded":9},"lucide:cog",{"title":77,"path":78,"stem":79,"icon":80,"excluded":9},"Security","\u002Fapplication\u002Fsettings\u002Fsecurity","2.application\u002F5.settings\u002F10.security","lucide:lock",{"title":82,"path":83,"stem":84,"icon":85,"excluded":9},"Notifications","\u002Fapplication\u002Fsettings\u002Fnotifications","2.application\u002F5.settings\u002F2.notifications","lucide:bell",{"title":87,"path":88,"stem":89,"icon":90,"excluded":9},"Type custom information","\u002Fapplication\u002Fsettings\u002Fcustom-information","2.application\u002F5.settings\u002F3.custom-information","lucide:file-text",{"title":92,"path":93,"stem":94,"icon":95,"excluded":9},"Appearance","\u002Fapplication\u002Fsettings\u002Fappearance","2.application\u002F5.settings\u002F4.appearance","lucide:palette",{"title":97,"path":98,"stem":99,"icon":25,"excluded":9},"Stocks","\u002Fapplication\u002Fsettings\u002Fstocks","2.application\u002F5.settings\u002F5.stocks",{"title":47,"path":101,"stem":102,"icon":103,"excluded":9},"\u002Fapplication\u002Fsettings\u002Fcatalog","2.application\u002F5.settings\u002F6.catalog","lucide:list",{"title":105,"path":106,"stem":107,"icon":108,"excluded":9},"History","\u002Fapplication\u002Fsettings\u002Fhistory","2.application\u002F5.settings\u002F7.history","lucide:baby",{"title":110,"path":111,"stem":112,"icon":113,"excluded":9},"Cloud & Account","\u002Fapplication\u002Fsettings\u002Fcloud","2.application\u002F5.settings\u002F8.cloud","lucide:cloud",{"title":115,"path":116,"stem":117,"icon":118,"excluded":9},"Manage data","\u002Fapplication\u002Fsettings\u002Fdata","2.application\u002F5.settings\u002F9.data","lucide:save","lucide:smartphone",{"title":121,"path":122,"stem":123,"children":124,"icon":113,"excluded":9},"Cloud Sync","\u002Fcloud-sync","3.cloud-sync\u002F1.index",[125,126],{"title":121,"path":122,"stem":123,"icon":8,"excluded":9},{"title":127,"path":128,"stem":129,"icon":8,"excluded":9},"Setup Cloud Sync","\u002Fcloud-sync\u002Fsetup","3.cloud-sync\u002F2.setup",{"title":131,"path":132,"stem":133,"children":134,"icon":152,"excluded":9},"Sharing","\u002Fsharing","4.sharing\u002F1.index",[135,136,140,144,148],{"title":131,"path":132,"stem":133,"icon":8,"excluded":9},{"title":137,"path":138,"stem":139,"icon":8,"excluded":9},"Setup history sharing","\u002Fsharing\u002Fsetup-history","4.sharing\u002F2.setup-history",{"title":141,"path":142,"stem":143,"icon":8,"excluded":9},"Setup stock sharing","\u002Fsharing\u002Fsetup-stock","4.sharing\u002F3.setup-stock",{"title":145,"path":146,"stem":147,"icon":8,"excluded":9},"Manage sharing","\u002Fsharing\u002Fmanage","4.sharing\u002F4.manage",{"title":149,"path":150,"stem":151,"icon":8,"excluded":9},"Image sharing","\u002Fsharing\u002Fimages","4.sharing\u002F5.images","lucide:share-2",{"title":154,"icon":155,"excluded":9,"path":156,"stem":157,"children":158,"page":9},"Contribute","lucide:users-round","\u002Fcontribute","50.contribute",[159,170],{"title":47,"path":160,"stem":161,"children":162,"icon":164,"excluded":9},"\u002Fcontribute\u002Fcatalog","50.contribute\u002F1.catalog\u002F1.index",[163,165],{"title":47,"path":160,"stem":161,"icon":164,"excluded":9},"lucide:file-stack",{"title":166,"path":167,"stem":168,"icon":169,"excluded":9},"Rules","\u002Fcontribute\u002Fcatalog\u002Frules","50.contribute\u002F1.catalog\u002F2.rules","lucide:file-lock",{"title":171,"path":172,"stem":173,"icon":174,"excluded":9},"Translate","\u002Fcontribute\u002Ftranslate","50.contribute\u002F2.translate","mdi:translate-variant",{"title":176,"path":177,"stem":178,"children":179,"icon":182,"excluded":9},"Public API","\u002Fapi","90.api\u002F1.index",[180,183,188,193,198,202],{"title":181,"path":177,"stem":178,"icon":182,"excluded":9},"Informations","lucide:code-xml",{"title":184,"path":185,"stem":186,"icon":187,"excluded":9},"Client Configuration","\u002Fapi\u002Fclient-configuration","90.api\u002F2.client-configuration","lucide:settings",{"title":189,"path":190,"stem":191,"icon":192,"excluded":9},"Authentication","\u002Fapi\u002Fauthentication","90.api\u002F3.authentication","lucide:user-lock",{"title":194,"path":195,"stem":196,"icon":197,"excluded":9},"API Usage","\u002Fapi\u002Fusage","90.api\u002F4.usage","lucide:file-code-2",{"title":199,"path":200,"stem":201,"icon":8,"excluded":9},"Add in DiapStash button","\u002Fapi\u002Fadd-in-button","90.api\u002F5.add-in-button",{"title":203,"path":204,"stem":205,"icon":206,"excluded":9},"Long Term Access","\u002Fapi\u002Flong-term-access","90.api\u002F6.long-term-access","lucide:infinity",{"title":208,"path":209,"stem":210,"icon":95,"excluded":9},"Visual Identity","\u002Fvisual-identity","90.visual-identity",{"title":212,"path":213,"stem":214,"icon":68,"excluded":9},"Awesome DiapStash","\u002Fawesome","91.awesome",{"title":216,"path":217,"stem":218,"icon":219,"excluded":9},"Questions & Answers","\u002Fqanda","94.QandA","uil:question-circle",{"title":221,"path":222,"stem":223,"icon":224,"excluded":9},"Known issues","\u002Fknownissues","95.knownissues","lucide:bug",{"title":226,"icon":227,"excluded":9,"path":228,"stem":229,"children":230,"page":9},"Experimental features","uil:flask","\u002Fexperimental","99.experimental",[231],{"title":232,"path":233,"stem":234,"icon":227,"excluded":9},"Beta","\u002Fexperimental\u002Fbeta","99.experimental\u002Fbeta",{"id":236,"title":203,"body":237,"description":1224,"excluded":9,"extension":1225,"icon":206,"links":1226,"meta":1236,"navigation":1231,"path":204,"seo":1237,"stem":205,"__hash__":1238},"docs\u002F90.api\u002F6.long-term-access.md",{"type":238,"value":239,"toc":1199},"minimark",[240,257,262,265,268,274,350,353,361,368,380,383,386,393,402,409,414,436,440,466,470,473,511,515,533,546,550,557,591,594,603,607,618,622,625,666,669,673,688,764,767,772,780,787,790,801,809,816,848,851,861,909,920,924,927,1025,1041,1053,1057,1068,1072,1076,1091,1096,1100,1103,1118,1125,1129,1132,1136,1141,1183,1186,1190,1195],[241,242,243],"warning",{},[244,245,246,250,251,256],"p",{},[247,248,249],"strong",{},"This mode is disabled by default and is not self-service."," It is granted client by client, after a\njustified request. See ",[252,253,255],"a",{"href":254},"#requesting-access","Requesting access"," below.",[258,259,261],"h2",{"id":260},"what-it-solves","What it solves",[244,263,264],{},"The standard API is built around a user who is present: you hold an access token for one user, it\nlives an hour, and you refresh it as needed.",[244,266,267],{},"That model breaks down when a server-side service follows its users over months. Keeping 500 users\nreadable means storing 500 refresh tokens, refreshing each of them on a schedule, handling\nrotation — and losing a user for good as soon as one of those tokens expires.",[244,269,270,273],{},[247,271,272],{},"Long term access"," replaces that with a single durable token per user. Your service stores it and\nreads that user's data whenever it needs to, authenticating only as itself.",[275,276,277,291],"table",{},[278,279,280],"thead",{},[281,282,283,286,289],"tr",{},[284,285],"th",{},[284,287,288],{},"Standard mode",[284,290,272],{},[292,293,294,306,317,328,339],"tbody",{},[281,295,296,300,303],{},[297,298,299],"td",{},"Credential per user",[297,301,302],{},"Refresh token, expires",[297,304,305],{},"Long term token, until revoked",[281,307,308,311,314],{},[297,309,310],{},"Keeping it alive",[297,312,313],{},"Refresh on a schedule, handle rotation",[297,315,316],{},"Nothing",[281,318,319,322,325],{},[297,320,321],{},"User must sign in again",[297,323,324],{},"Yes, when the refresh token expires",[297,326,327],{},"No",[281,329,330,333,336],{},[297,331,332],{},"User can revoke",[297,334,335],{},"On logout \u002F token revocation",[297,337,338],{},"Any time, from their account page",[281,340,341,344,347],{},[297,342,343],{},"Endpoints",[297,345,346],{},"The public API",[297,348,349],{},"The same public API",[258,351,255],{"id":352},"requesting-access",[241,354,355],{},[244,356,357,360],{},[247,358,359],{},"We refuse by default."," Long term access is granted only when the need is genuinely justified and\ncoherent with what your service does. If a request does not make that case, the answer is no.",[244,362,363,364,367],{},"The ",[252,365,366],{"href":190},"standard per-user mode"," remains the one to reach for. It covers almost\nevery integration, and if your feature can be built with it, that is what we will point you to\nrather than opening this one.",[244,369,370,371,374,375,379],{},"It is also ",[247,372,373],{},"not a key to the whole API",". Only a deliberately small set of endpoints accepts a long\nterm access token — see ",[252,376,378],{"href":377},"#reading-data","Reading data"," for the current list. Everything else stays\nreachable with a regular user token only, and being granted this mode does not change that. If what\nyou need is not in that list, this is not the answer to your problem.",[244,381,382],{},"Long term access hands your service long-lived, unattended access to the personal data of many\npeople. We open it deliberately, not on demand, and we need to understand your project before we do.",[244,384,385],{},"Reach us on",[387,388],"u-button",{"icon":389,"label":390,"to":391,"variant":392},"simple-icons:discord","Discord","https:\u002F\u002Fdiapstash.com\u002Fdiscord","link",[244,394,395,396,401],{},"or through the\n",[387,397],{"icon":398,"label":399,"to":400,"variant":392},"lucide:mail","contact form","https:\u002F\u002Fdiapstash.com\u002Fcontact",".",[244,403,404,405,408],{},"Describe your request ",[247,406,407],{},"precisely"," — a vague one will be turned down rather than chased up.",[410,411,413],"h3",{"id":412},"your-project","Your project",[415,416,417,424,430],"ul",{},[418,419,420,423],"li",{},[247,421,422],{},"What your service does",", in full: what it is for, who runs it, whether it is free or paid, open\nsource or not, and where it is hosted.",[418,425,426,429],{},[247,427,428],{},"Who your users are",", and roughly how many of them you expect to enroll.",[418,431,432,435],{},[247,433,434],{},"How your users reach it"," — a website, a mobile app, a home automation setup, a research protocol…",[410,437,439],{"id":438},"your-use-of-the-diapstash-api","Your use of the DiapStash API",[415,441,442,448,454,460],{},[418,443,444,447],{},[247,445,446],{},"Which endpoints you already call",", and how often.",[418,449,450,453],{},[247,451,452],{},"Why the standard per-user mode does not fit"," — be concrete: what breaks, or what you cannot\nbuild without long term access. This is the claim we weigh most heavily, and the one most requests\nfail on.",[418,455,456,459],{},[247,457,458],{},"Which long term scopes you need",", and what each one is for. Asking for the narrowest set that\nmakes your feature work makes the request much easier to grant.",[418,461,462,465],{},[247,463,464],{},"How often you will read"," each enrolled user.",[410,467,469],{"id":468},"what-you-do-with-the-data","What you do with the data",[244,471,472],{},"This is the part we read most carefully. Our users are trusting you with intimate, personal data.",[415,474,475,481,487,493,499,505],{},[418,476,477,480],{},[247,478,479],{},"What you store",", where it is hosted, and for how long.",[418,482,483,486],{},[247,484,485],{},"How it is secured",": encryption at rest and in transit, who on your side can access it, and how\nlong term access tokens themselves are protected.",[418,488,489,492],{},[247,490,491],{},"Who else sees it",": any third party, subprocessor, or analytics provider it passes through.",[418,494,495,498],{},[247,496,497],{},"That you do not resell, trade, or share the data",", and that you do not use it to train models or\nbuild advertising profiles. We will ask you to state this explicitly.",[418,500,501,504],{},[247,502,503],{},"What happens when a user revokes",", or deletes their account on your side: how their data is\ndeleted, and within what delay.",[418,506,507,510],{},[247,508,509],{},"A link to your privacy policy",", covering the above.",[410,512,514],{"id":513},"requirements-your-client-must-meet","Requirements your client must meet",[516,517,518,530],"ol",{},[418,519,520,521,524,525,529],{},"It must be a ",[247,522,523],{},"confidential backend client"," — an application type of ",[526,527,528],"code",{},"API \u002F Server",", with a client\nsecret. A Javascript Web App or a native app can never be granted this mode: its secret cannot be\nkept.",[418,531,532],{},"It must be able to keep long term access tokens secret, at rest, on your own servers.",[244,534,535,536,538,539,545],{},"Once we open the mode on your client, a ",[247,537,272],{}," section appears on it in your\n",[252,540,544],{"href":541,"rel":542},"https:\u002F\u002Faccount.diapstash.com\u002Faccount#api",[543],"nofollow","API access"," tab. You pick the long term scopes there\nyourself, and can take one back at any time by unticking it.",[258,547,549],{"id":548},"scopes","Scopes",[244,551,552,553,556],{},"Long term access uses its own scope family, separate from the regular ",[526,554,555],{},"cloud-sync.*"," scopes. Asking\nfor one of them in an ordinary sign-in is what turns it into a long term enrollment.",[275,558,559,569],{},[278,560,561],{},[281,562,563,566],{},[284,564,565],{},"Scope",[284,567,568],{},"Description",[292,570,571,581],{},[281,572,573,578],{},[297,574,575],{},[526,576,577],{},"cloud-sync.permanent.latest-change",[297,579,580],{},"Read the latest change of enrolled users",[281,582,583,588],{},[297,584,585],{},[526,586,587],{},"cloud-sync.permanent.stats",[297,589,590],{},"Read aggregated statistics of enrolled users",[244,592,593],{},"Users see these on the consent screen with an explicit warning that the access survives their session.",[241,595,596],{},[244,597,598,599,602],{},"Until we open the mode on your client, these scopes do not exist for it: an authorization request\nasking for one is refused with ",[526,600,601],{},"invalid_scope",". That refusal is the gate — there is nothing else to\nconfigure on your side.",[258,604,606],{"id":605},"enrolling-a-user","Enrolling a user",[244,608,609,610,613,614,617],{},"Enrollment happens ",[247,611,612],{},"once per user",", against ",[526,615,616],{},"account.diapstash.com",", in two steps.",[410,619,621],{"id":620},"_1-get-the-users-consent","1. Get the user's consent",[244,623,624],{},"An ordinary authorization code flow. The only difference from a regular sign-in is the scopes you\nask for:",[626,627,632],"pre",{"className":628,"code":629,"language":630,"meta":631,"style":631},"language-http shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","https:\u002F\u002Faccount.diapstash.com\u002Foidc\u002Fauth?\n  client_id=YOUR_CLIENT_ID\n  &redirect_uri=YOUR_REDIRECT_URI\n  &response_type=code\n  &scope=openid cloud-sync.permanent.latest-change cloud-sync.permanent.stats\n","http","",[526,633,634,642,648,654,660],{"__ignoreMap":631},[635,636,639],"span",{"class":637,"line":638},"line",1,[635,640,641],{},"https:\u002F\u002Faccount.diapstash.com\u002Foidc\u002Fauth?\n",[635,643,645],{"class":637,"line":644},2,[635,646,647],{},"  client_id=YOUR_CLIENT_ID\n",[635,649,651],{"class":637,"line":650},3,[635,652,653],{},"  &redirect_uri=YOUR_REDIRECT_URI\n",[635,655,657],{"class":637,"line":656},4,[635,658,659],{},"  &response_type=code\n",[635,661,663],{"class":637,"line":662},5,[635,664,665],{},"  &scope=openid cloud-sync.permanent.latest-change cloud-sync.permanent.stats\n",[244,667,668],{},"Exchange the code at the token endpoint as usual, and keep the resulting access token for the next\nstep. It is short-lived, so do this right away.",[410,670,672],{"id":671},"_2-exchange-it-for-a-long-term-access-token","2. Exchange it for a long term access token",[626,674,676],{"className":628,"code":675,"language":630,"meta":631,"style":631},"POST https:\u002F\u002Faccount.diapstash.com\u002Fapi\u002Flong-term-access\u002Ftokens\nAuthorization: Bearer \u003CTHE USER ACCESS TOKEN FROM STEP 1>\n",[526,677,678,683],{"__ignoreMap":631},[635,679,680],{"class":637,"line":638},[635,681,682],{},"POST https:\u002F\u002Faccount.diapstash.com\u002Fapi\u002Flong-term-access\u002Ftokens\n",[635,684,685],{"class":637,"line":644},[635,686,687],{},"Authorization: Bearer \u003CTHE USER ACCESS TOKEN FROM STEP 1>\n",[626,689,693],{"className":690,"code":691,"language":692,"meta":631,"style":631},"language-json shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","{\n  \"token\": \"dspa_a1b2c3d4e5f60718293a4b5c_XSyR...\",\n  \"scopes\": [\"cloud-sync.permanent.latest-change\", \"cloud-sync.permanent.stats\"]\n}\n","json",[526,694,695,701,728,759],{"__ignoreMap":631},[635,696,697],{"class":637,"line":638},[635,698,700],{"class":699},"sMK4o","{\n",[635,702,703,706,710,713,716,719,723,725],{"class":637,"line":644},[635,704,705],{"class":699},"  \"",[635,707,709],{"class":708},"spNyl","token",[635,711,712],{"class":699},"\"",[635,714,715],{"class":699},":",[635,717,718],{"class":699}," \"",[635,720,722],{"class":721},"sfazB","dspa_a1b2c3d4e5f60718293a4b5c_XSyR...",[635,724,712],{"class":699},[635,726,727],{"class":699},",\n",[635,729,730,732,734,736,738,741,743,745,747,750,752,754,756],{"class":637,"line":650},[635,731,705],{"class":699},[635,733,548],{"class":708},[635,735,712],{"class":699},[635,737,715],{"class":699},[635,739,740],{"class":699}," [",[635,742,712],{"class":699},[635,744,577],{"class":721},[635,746,712],{"class":699},[635,748,749],{"class":699},",",[635,751,718],{"class":699},[635,753,587],{"class":721},[635,755,712],{"class":699},[635,757,758],{"class":699},"]\n",[635,760,761],{"class":637,"line":656},[635,762,763],{"class":699},"}\n",[244,765,766],{},"That access token is the whole authorization: it says which user consented, to which client, and for\nwhich scopes. The long term access token inherits exactly those scopes — never more.",[241,768,769],{},[244,770,771],{},"Because that token alone can create a long term access, treat it as sensitive for the minutes it\nlives: keep it server-side, never log it, and exchange it immediately. Only a user token is accepted\nhere — minting acts on behalf of a user, so one has to have consented.",[241,773,774],{},[244,775,776,779],{},[247,777,778],{},"The token is returned once and never again."," We only store a hash of it — we cannot show it to you\nlater. Store it before you close the response, and treat it like a password.",[244,781,782,783,786],{},"Re-enrolling the same user ",[247,784,785],{},"rotates"," their token: the previous one stops working immediately.",[258,788,378],{"id":789},"reading-data",[244,791,792,793,796,797,800],{},"Long term access does not add endpoints. It adds a ",[247,794,795],{},"second way to authenticate on the ordinary\nones",": the routes below accept a ",[526,798,799],{},"cloud-sync.permanent.*"," scope and work in both modes, returning\nthe exact same payload.",[626,802,807],{"className":803,"code":805,"language":806},[804],"language-text","regular    Authorization: Bearer \u003CUSER ACCESS TOKEN>\n           DS-API-CLIENT-ID: \u003CCLIENT ID>\n\nlong term  Authorization: Bearer \u003CLONG TERM TOKEN>.\u003CYOUR CLIENT SECRET>\n","text",[526,808,805],{"__ignoreMap":631},[244,810,811,812,815],{},"The long term credential is a single bearer token: the user's long term access token, a dot, then your\nclient secret. Its ",[526,813,814],{},"dspa_"," prefix is what tells it apart from a user token.",[626,817,821],{"className":818,"code":819,"language":820,"meta":631,"style":631},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","curl -H \"Authorization: Bearer dspa_a1b2c3d4e5f60718293a4b5c_XSyR....YOUR_CLIENT_SECRET\" \\\n  https:\u002F\u002Fapi.diapstash.com\u002Fapi\u002Fv1\u002Fhistory\u002Flatest-change\n","bash",[526,822,823,843],{"__ignoreMap":631},[635,824,825,829,832,834,837,839],{"class":637,"line":638},[635,826,828],{"class":827},"sBMFI","curl",[635,830,831],{"class":721}," -H",[635,833,718],{"class":699},[635,835,836],{"class":721},"Authorization: Bearer dspa_a1b2c3d4e5f60718293a4b5c_XSyR....YOUR_CLIENT_SECRET",[635,838,712],{"class":699},[635,840,842],{"class":841},"sTEyZ"," \\\n",[635,844,845],{"class":637,"line":644},[635,846,847],{"class":721},"  https:\u002F\u002Fapi.diapstash.com\u002Fapi\u002Fv1\u002Fhistory\u002Flatest-change\n",[244,849,850],{},"Both halves are needed. Our database only stores a hash of the long term access token, and your client\nsecret on its own names no user.",[852,853,854],"note",{},[244,855,856,857,860],{},"The credential is ",[247,858,859],{},"static",": no token endpoint round-trip before a call, nothing to refresh, nothing\nto cache. One request per read.",[275,862,863,876],{},[278,864,865],{},[281,866,867,870,873],{},[284,868,869],{},"Endpoint",[284,871,872],{},"Long term scope",[284,874,875],{},"Regular scope",[292,877,878,894],{},[281,879,880,885,889],{},[297,881,882],{},[526,883,884],{},"GET \u002Fapi\u002Fv1\u002Fhistory\u002Flatest-change",[297,886,887],{},[526,888,577],{},[297,890,891],{},[526,892,893],{},"cloud-sync.history",[281,895,896,901,905],{},[297,897,898],{},[526,899,900],{},"GET \u002Fapi\u002Fv1\u002Fhistory\u002Fstats",[297,902,903],{},[526,904,587],{},[297,906,907],{},[526,908,893],{},[244,910,911,912,915,916,919],{},"Everything else — the paginated ",[526,913,914],{},"\u002Fhistory\u002Fchanges"," and ",[526,917,918],{},"\u002Fhistory\u002Faccidents",", stocks, types — stays\nreachable only with a regular user token. Long term access deliberately covers the two reads a\nserver-side service needs to follow a user over time, not the whole API.",[410,921,923],{"id":922},"error-responses","Error responses",[244,925,926],{},"A long term call fails as a whole; there is no per-user status to read.",[275,928,929,942],{},[278,930,931],{},[281,932,933,936,939],{},[284,934,935],{},"Status",[284,937,938],{},"Meaning",[284,940,941],{},"What to do",[292,943,944,957,970,983,999,1012],{},[281,945,946,951,954],{},[297,947,948],{},[526,949,950],{},"401",[297,952,953],{},"Credential unknown, malformed, or the client secret does not match",[297,955,956],{},"Check your configuration — this is not necessarily a revocation",[281,958,959,964,967],{},[297,960,961],{},[526,962,963],{},"401 PermanentAccessRevoked",[297,965,966],{},"The access existed and has been revoked",[297,968,969],{},"Delete your copy of the token; it will never work again",[281,971,972,977,980],{},[297,973,974],{},[526,975,976],{},"401 NoCloudSyncLinked",[297,978,979],{},"The account has no Cloud Sync linked",[297,981,982],{},"Ask the user to link it in the app",[281,984,985,990,993],{},[297,986,987],{},[526,988,989],{},"403 CloudSyncInactive",[297,991,992],{},"Cloud Sync silent for over 90 days",[297,994,995,998],{},[247,996,997],{},"Keep the token"," — access resumes on its own",[281,1000,1001,1006,1009],{},[297,1002,1003],{},[526,1004,1005],{},"403",[297,1007,1008],{},"Neither your client nor the user granted the scope you asked for",[297,1010,1011],{},"Re-enroll asking for that scope",[281,1013,1014,1019,1022],{},[297,1015,1016],{},[526,1017,1018],{},"404",[297,1020,1021],{},"Nothing recorded for that user (current change only)",[297,1023,1024],{},"Nothing; the access is fine",[852,1026,1027],{},[244,1028,1029,1030,1032,1033,1036,1037,1040],{},"A plain ",[526,1031,950],{}," covers an unknown token and a wrong client secret alike, on purpose: we do not confirm\nwhether a token ever existed to anyone who cannot already prove it. You only get\n",[526,1034,1035],{},"PermanentAccessRevoked"," when both halves of your credential are correct — which is why it is safe to\ntell you. We never say ",[247,1038,1039],{},"who"," revoked it.",[1042,1043,1044],"tip",{},[244,1045,1046,1048,1049,1052],{},[526,1047,989],{}," is ",[247,1050,1051],{},"not"," a revocation. A user who stops syncing for a few months and comes\nback keeps working with the same token — do not delete it.",[258,1054,1056],{"id":1055},"rate-limits","Rate limits",[244,1058,1059,1060,1063,1064,1067],{},"Per client, per hour, returned in the standard ",[526,1061,1062],{},"RateLimit"," response headers — the same budget as the\nrest of the public API. Your client is identified by the credential itself, so ",[526,1065,1066],{},"DS-API-CLIENT-ID"," is\nnot needed in long term mode.",[258,1069,1071],{"id":1070},"revoking","Revoking",[410,1073,1075],{"id":1074},"the-user","The user",[244,1077,1078,1079,1082,1083,1088,1089,401],{},"Users see every service holding a long term access in the ",[247,1080,1081],{},"Connected services"," tab of\n",[252,1084,1087],{"href":1085,"rel":1086},"https:\u002F\u002Faccount.diapstash.com",[543],"their account",", with the scopes granted, when it was granted, and when\nyou last used it. One click revokes it, and your very next call returns ",[526,1090,1035],{},[852,1092,1093],{},[244,1094,1095],{},"Design for this. Revocation is immediate, silent, and does not warn you in advance.",[410,1097,1099],{"id":1098},"your-service","Your service",[244,1101,1102],{},"Drop a token you no longer need:",[626,1104,1106],{"className":628,"code":1105,"language":630,"meta":631,"style":631},"DELETE https:\u002F\u002Faccount.diapstash.com\u002Fapi\u002Flong-term-access\u002Ftokens\nAuthorization: Bearer \u003CLONG TERM TOKEN>.\u003CYOUR CLIENT SECRET>\n",[526,1107,1108,1113],{"__ignoreMap":631},[635,1109,1110],{"class":637,"line":638},[635,1111,1112],{},"DELETE https:\u002F\u002Faccount.diapstash.com\u002Fapi\u002Flong-term-access\u002Ftokens\n",[635,1114,1115],{"class":637,"line":644},[635,1116,1117],{},"Authorization: Bearer \u003CLONG TERM TOKEN>.\u003CYOUR CLIENT SECRET>\n",[244,1119,1120,1121,1124],{},"The credential names the token to drop, so there is nothing to send in the body. Always answers\n",[526,1122,1123],{},"204",", whether or not the token existed.",[410,1126,1128],{"id":1127},"us","Us",[244,1130,1131],{},"We can withdraw the mode from your client. Every token you hold stops working at once. We do this if\nthe feature is used outside the scope of your request, or on abuse reports.",[258,1133,1135],{"id":1134},"handling-the-tokens","Handling the tokens",[241,1137,1138],{},[244,1139,1140],{},"One long term access token is a durable key to one person's data. Together, your token store is the most\nsensitive thing your integration holds.",[415,1142,1143,1149,1159,1165,1177],{},[418,1144,1145,1148],{},[247,1146,1147],{},"Encrypt them at rest."," They are equivalent to passwords, not to identifiers.",[418,1150,1151,1154,1155,1158],{},[247,1152,1153],{},"Never log them",", and never put them in a URL — they belong in the ",[526,1156,1157],{},"Authorization"," header, which\nmost logging setups already redact.",[418,1160,1161,1164],{},[247,1162,1163],{},"Never expose them to a browser"," or ship them to a mobile app.",[418,1166,1167,1170,1171,1173,1174,1176],{},[247,1168,1169],{},"Delete your copy"," as soon as a token comes back ",[526,1172,1035],{},". A plain ",[526,1175,950],{}," is more\nlikely a configuration problem than a revocation — check before discarding anything.",[418,1178,1179,1182],{},[247,1180,1181],{},"Delete a user's token"," when they delete their account on your side. Do not wait for them to also\nfind the DiapStash account page.",[244,1184,1185],{},"Deleting a DiapStash account revokes every long term access on it.",[258,1187,1189],{"id":1188},"support","Support",[244,1191,1192,1193],{},"Questions or issues: ",[387,1194],{"icon":389,"label":390,"to":391,"variant":392},[1196,1197,1198],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}",{"title":631,"searchDepth":638,"depth":644,"links":1200},[1201,1202,1208,1209,1213,1216,1217,1222,1223],{"id":260,"depth":644,"text":261},{"id":352,"depth":644,"text":255,"children":1203},[1204,1205,1206,1207],{"id":412,"depth":650,"text":413},{"id":438,"depth":650,"text":439},{"id":468,"depth":650,"text":469},{"id":513,"depth":650,"text":514},{"id":548,"depth":644,"text":549},{"id":605,"depth":644,"text":606,"children":1210},[1211,1212],{"id":620,"depth":650,"text":621},{"id":671,"depth":650,"text":672},{"id":789,"depth":644,"text":378,"children":1214},[1215],{"id":922,"depth":650,"text":923},{"id":1055,"depth":644,"text":1056},{"id":1070,"depth":644,"text":1071,"children":1218},[1219,1220,1221],{"id":1074,"depth":650,"text":1075},{"id":1098,"depth":650,"text":1099},{"id":1127,"depth":650,"text":1128},{"id":1134,"depth":644,"text":1135},{"id":1188,"depth":644,"text":1189},"Read your users' data from your own servers, without them signing in again. Restricted mode, granted on request.","md",[1227,1233],{"label":1228,"icon":1229,"target":1230,"external":1231,"to":1232},"Swagger","simple-icons:swagger","_blank",true,"https:\u002F\u002Fapi.diapstash.com\u002Fapi\u002Fdocs",{"label":1234,"icon":1235,"target":1230,"external":1231,"to":1085},"DiapStash Account","lucide:user",{},{"title":203,"description":1224},"2dn__PRrHNkJrBjWLOQccjFNkEwpJKCDlYlvSXlvcHU",1789127921486]