e-Próspera
Releases

OAuth device authorization and tax reads

2026-08-12 · API — Additive OAuth endpoints and scopes now support the official CLI, consented entities, and read-only tax data.

View as Markdown

API

Additive public API update. Existing authorization-code integrations continue to work without changes.

The public OAuth surface now supports the official CLI's device authorization flow and read-only access to personal or consented legal-entity tax records.

OAuth additions

  • The device authorization endpoint issues a user code and verification URL for the registered official CLI.
  • The token endpoint supports device-code polling by that public client.
  • The revocation endpoint accepts the official public client without an embedded secret.
  • OpenID discovery publishes the device and revocation capabilities supported by the server.

The device flow is currently reserved for the official CLI. Third-party OAuth clients continue to use the authorization-code flow with PKCE.

New consented data

The following OAuth scopes are available:

ScopeAccess
eprospera:entity.readProfiles for legal entities selected during consent
eprospera:entity.documents.readDocuments for selected legal entities
eprospera:person.tax.readThe signed-in user's tax status and filings
eprospera:entity.tax.readTax data for selected legal entities

New read-only resources include:

Entity selection during consent does not override representation checks. If a user stops representing an entity, later requests stop returning its data. These endpoints do not create, modify, submit, or pay tax filings.

See OAuth 2.0 / OpenID Connect for the protocol details and Tax and legal-entity data for examples and confidential-data handling.

On this page