# OAuth endpoints

> Every endpoint an org admin's OAuth token can call in the BloomText API, the admin's own conversations and the Patient API, plus the authorization server's URLs.

Source: https://www.bloomtext.com/developers/api/reference/oauth-endpoints/

All 37 endpoints an org admin's [OAuth access token](https://www.bloomtext.com/developers/api/oauth/) can call: the admin's own conversations, which only OAuth reaches, and every [Patient API endpoint](https://www.bloomtext.com/developers/api/reference/patient-api-endpoints/). Each links to its full reference page, with parameters, errors, and code samples.

```text filename="Base URL"
https://api.bloomtext.com/v1
```

Send the access token as `Authorization: Bearer $BLOOMTEXT_ACCESS_TOKEN`. The scope column is what the admin must have approved; see [Scopes](https://www.bloomtext.com/developers/api/authentication/#scopes).

## Authorization server

Your app gets and manages tokens with these standard OAuth 2.0 URLs. They return OAuth errors, not problem details. See [Connect with OAuth](https://www.bloomtext.com/developers/api/oauth/).

| Method | URL | Used to |
| --- | --- | --- |
| GET | `https://app.bloomtext.com/oauth/authorize` | [Send the admin to sign in and approve your app](https://www.bloomtext.com/developers/api/oauth/#send-the-user-to-bloomtext) |
| POST | `https://app.bloomtext.com/oauth/token` | [Exchange a code for tokens](https://www.bloomtext.com/developers/api/oauth/#exchange-the-code-for-tokens) and [refresh an access token](https://www.bloomtext.com/developers/api/oauth/#refresh-an-access-token) |
| POST | `https://app.bloomtext.com/oauth/revoke` | [Disconnect a user](https://www.bloomtext.com/developers/api/oauth/#when-a-connection-ends) |
| GET | `https://app.bloomtext.com/.well-known/oauth-authorization-server` | [Discover the authorization server](https://www.bloomtext.com/developers/api/oauth/#server-metadata) |
| GET | `https://api.bloomtext.com/.well-known/oauth-protected-resource/v1` | [Discover the API as a protected resource](https://www.bloomtext.com/developers/api/oauth/#server-metadata) |

## The admin's own conversations

OAuth only. These reach the conversations the connected admin is in, and the organization's staff directory.

### Profile

The person who connected your app with OAuth, and the grant itself.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/me` | [Retrieve the profile](https://www.bloomtext.com/developers/api/reference/get-profile/) | `messages.read` |

### Messages

The connected person's own messages, in team chats and patient conversations.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/me/messages` | [List messages](https://www.bloomtext.com/developers/api/reference/list-messages/) | `messages.read` |
| GET | `/me/messages/{messageId}` | [Retrieve a message](https://www.bloomtext.com/developers/api/reference/get-message/) | `messages.read` |
| POST | `/me/conversations/{conversationId}/messages` | [Send a message](https://www.bloomtext.com/developers/api/reference/create-message/) | `messages.write` |

### Reactions

Emoji reactions on the connected person's messages.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/me/messages/{messageId}/reactions` | [List reactions](https://www.bloomtext.com/developers/api/reference/list-reactions/) | `messages.read` |
| POST | `/me/messages/{messageId}/reactions` | [Add a reaction](https://www.bloomtext.com/developers/api/reference/create-reaction/) | `messages.write` |
| DELETE | `/me/messages/{messageId}/reactions` | [Remove a reaction](https://www.bloomtext.com/developers/api/reference/delete-reaction/) | `messages.write` |

### Conversations

The connected person's own conversations, team chats and patient conversations.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/me/conversations` | [List conversations](https://www.bloomtext.com/developers/api/reference/list-conversations/) | `messages.read` |
| GET | `/me/conversations/{conversationId}` | [Retrieve a conversation](https://www.bloomtext.com/developers/api/reference/get-conversation/) | `messages.read` |

### Participants

Staff and patients in one of the connected person's conversations.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/me/conversations/{conversationId}/participants` | [List participants](https://www.bloomtext.com/developers/api/reference/list-participants/) | `messages.read` |

### Users

Staff members of the connected person's organization.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/users` | [List users](https://www.bloomtext.com/developers/api/reference/list-users/) | `messages.read` |
| GET | `/users/{userId}` | [Retrieve a user](https://www.bloomtext.com/developers/api/reference/get-user/) | `messages.read` |

## Patient API

The same endpoints an API key calls. With OAuth, [phone numbers](https://www.bloomtext.com/developers/api/reference/list-phone-numbers/) are limited to the admin's teams' numbers, and messages come from the admin rather than a key.

### Organization

The organization a credential belongs to.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/organization` | [Retrieve the organization](https://www.bloomtext.com/developers/api/reference/get-organization/) | Any |

### Patients

Patient records, always found by patient ID, phone number, or MRN.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/patients` | [Find patients](https://www.bloomtext.com/developers/api/reference/list-patients/) | `patients.read` |
| POST | `/patients` | [Create a patient](https://www.bloomtext.com/developers/api/reference/create-patient/) | `patients.write` |
| GET | `/patients/{patientId}` | [Retrieve a patient](https://www.bloomtext.com/developers/api/reference/get-patient/) | `patients.read` |
| PATCH | `/patients/{patientId}` | [Update a patient](https://www.bloomtext.com/developers/api/reference/update-patient/) | `patients.write` |
| DELETE | `/patients/{patientId}` | [Delete a patient](https://www.bloomtext.com/developers/api/reference/delete-patient/) | `patients.write` |

### Patient imports

Bulk imports of patient records.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| POST | `/patient-imports` | [Import patients](https://www.bloomtext.com/developers/api/reference/create-patient-import/) | `patients.write` |
| GET | `/patient-imports/{importId}` | [Retrieve an import](https://www.bloomtext.com/developers/api/reference/get-patient-import/) | `patients.write` |

### Patient messages

Messages with patients: send to a patient by ID or phone number, read patient messages by time range, and check delivery.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/patient-messages` | [List patient messages](https://www.bloomtext.com/developers/api/reference/list-patient-messages/) | `messages.read` |
| POST | `/patient-messages` | [Send a message to a patient](https://www.bloomtext.com/developers/api/reference/send-message/) | `messages.write` |
| GET | `/patient-messages/{messageId}` | [Retrieve a patient message](https://www.bloomtext.com/developers/api/reference/get-patient-message/) | `messages.read` |

### Patient conversations

Conversations with patients, one per patient and clinic phone number.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/patient-conversations` | [List patient conversations](https://www.bloomtext.com/developers/api/reference/list-patient-conversations/) | `messages.read` |
| GET | `/patient-conversations/{conversationId}` | [Retrieve a patient conversation](https://www.bloomtext.com/developers/api/reference/get-patient-conversation/) | `messages.read` |

### Phone numbers

The clinic phone numbers messages to patients come from, and the team each belongs to.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/phone-numbers` | [List phone numbers](https://www.bloomtext.com/developers/api/reference/list-phone-numbers/) | `messages.read` |

### Campaigns

One message sent to many patients from a clinic phone number, with per-patient delivery.

| Method | Path | Endpoint | Scope |
| --- | --- | --- | --- |
| GET | `/campaigns` | [List campaigns](https://www.bloomtext.com/developers/api/reference/list-campaigns/) | `messages.read` |
| POST | `/campaigns` | [Create a campaign](https://www.bloomtext.com/developers/api/reference/create-campaign/) | `messages.write` |
| GET | `/campaigns/{campaignId}` | [Retrieve a campaign](https://www.bloomtext.com/developers/api/reference/get-campaign/) | `messages.read` |
| PATCH | `/campaigns/{campaignId}` | [Update a campaign](https://www.bloomtext.com/developers/api/reference/update-campaign/) | `messages.write` |
| DELETE | `/campaigns/{campaignId}` | [Delete a campaign](https://www.bloomtext.com/developers/api/reference/delete-campaign/) | `messages.write` |
| GET | `/campaigns/{campaignId}/recipients` | [List campaign recipients](https://www.bloomtext.com/developers/api/reference/list-campaign-recipients/) | `messages.read` |
| POST | `/campaigns/{campaignId}/recipients` | [Add campaign recipients](https://www.bloomtext.com/developers/api/reference/add-campaign-recipients/) | `messages.write` |
| POST | `/campaigns/{campaignId}/recipients/remove` | [Remove campaign recipients](https://www.bloomtext.com/developers/api/reference/remove-campaign-recipients/) | `messages.write` |
| POST | `/campaigns/{campaignId}/start` | [Start a campaign](https://www.bloomtext.com/developers/api/reference/start-campaign/) | `messages.write` |
| POST | `/campaigns/{campaignId}/pause` | [Pause a campaign](https://www.bloomtext.com/developers/api/reference/pause-campaign/) | `messages.write` |
| POST | `/campaigns/{campaignId}/stop` | [Stop a campaign](https://www.bloomtext.com/developers/api/reference/stop-campaign/) | `messages.write` |
