Skip to content
Smartlife Docs
FR
Stored only in this browser (never sent to this server) and reused on every “Test this endpoint” page below.
Scopes granted to this token (see the response received during authentication):
The “Test” buttons below stay disabled until the scope required by the endpoint is ticked here.

Overview

The platform exposes an HTTP API that lets a third-party application read the data of your projects and rentals. Every endpoint returns JSON; all of them are read-only (GET method) except the one documented as a write endpoint.

Endpoint base URL (production): https://construction.my-smartlife.fr/api/

Every endpoint requires OAuth2 authentication. A call without a token, or with an invalid/expired token, returns a 401 error (the API messages are in French):
curl https://construction.my-smartlife.fr/api/projects/list

{"detail":"Jeton OAuth manquant"}

This documentation spans several pages

This page covers authentication. The following pages detail each available endpoint, with a built-in tester to try it directly from your browser.

Authenticate: two possible OAuth2 flows

Depending on your situation, two ways of getting an access token (access_token) are available. Both produce a token used the same way, in the HTTP header:
Authorization: Bearer YOUR_ACCESS_TOKEN
Diagram of the two OAuth2 flows: connected application and partner integration
The two ways to get a token, then its use in the Authorization header.

Flow 1: application connected from your profile (recommended)

This is the flow to use if you are building an application that must access your own projects (or those of a user who gives their consent).

1. Register your application
From your profile, “OAuth application” tab, create an application: you get a client_id and a client_secret (shown only once), as well as a redirect URL (redirect_uri) and allowed scopes.

2. Ask for the user's authorisation
Redirect the user to the consent screen:
GET https://construction.my-smartlife.fr/oauth/authorize.php
  ?client_id=YOUR_CLIENT_ID
  &redirect_uri=YOUR_REDIRECT_URI
  &scope=projects:read rentals:read
  &state=a_random_value
Once accepted, the user is redirected to your redirect_uri with a temporary code (valid for 2 minutes): ?code=XXXX&state=...

3. Exchange the code for a token
curl -X POST https://construction.my-smartlife.fr/oauth/token.php \
  -d 'grant_type=authorization_code' \
  -d 'code=XXXX' \
  -d 'client_id=YOUR_CLIENT_ID' \
  -d 'client_secret=YOUR_CLIENT_SECRET' \
  -d 'redirect_uri=YOUR_REDIRECT_URI'
Response:
{
  "access_token": "...",
  "refresh_token": "...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "scope": "projects:read rentals:read"
}

Data scope

A token obtained through this flow only gives access to the projects belonging to the account that accepted the connection — never to those of another user.

4. Renew the token
The token expires after 1 hour. Use the refresh_token (whose value does not change as long as it is not used) to get a new one without going through the consent screen again:
curl -X POST https://construction.my-smartlife.fr/oauth/token.php \
  -d 'grant_type=refresh_token' \
  -d 'refresh_token=YOUR_REFRESH_TOKEN' \
  -d 'client_id=YOUR_CLIENT_ID' \
  -d 'client_secret=YOUR_CLIENT_SECRET'
You can revoke access at any time from the “OAuth application” tab of the profile: the current token then stops working immediately.

Flow 2: partner integration (client_credentials)

This flow is reserved for server-to-server integrations for which a Smartlife administrator has created a dedicated client, linked to a fixed list of projects (useful for an internal dashboard or a trusted partner, for example).

An administrator creates the client:
python app/create_oauth_client.py partenaire-1 \
  --projects 12,18 \
  --scopes project:read,rental:read
Your application then exchanges its credentials for a token:
curl -u 'partenaire-1:SECRET' -X POST https://construction.my-smartlife.fr/oauth/token \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  --data 'grant_type=client_credentials&scope=project:read rental:read'
This flow has neither a consent screen nor a refresh_token: simply request a new token with the same credentials once it has expired (1 hour).

Ready to try?

Once you have your token (through either flow), go to the next page: you can paste it into the built-in tester and call the real endpoints directly from this documentation.


Link copied!