BETTERBOOKS / DEVELOPERS
BetterBooks API authentication and access
BetterBooks API authentication uses IOP sign-in, and company membership plus book context — not the login alone — decide what a request may access.
Use the established sign-in flow
The BetterBooks application signs in through IOP. Do not collect IOP passwords in your integration or copy browser refresh tokens. Third-party client registration and token issuance require an explicitly supported identity configuration.
Identity is not company access
GET /api/v1/auth/me resolves the authenticated BetterBooks profile and effective access. Sign-in does not automatically authorize every company. Tenant switching is an authorized application operation, not permission to supply an arbitrary tenant identifier.
Book context
Book-scoped operations use the selected accounting book. The application sends X-Book-Id where required; endpoints can also define their own book parameters. The backend must authorize the requested book. A header alone never grants access.