You read TaxRock data on a TaxRock user’s behalf, after the user grants
consent once. It is a standard OAuth 2.0 Authorization Code + PKCE integration.
How it works
1
The user connects (once)
You send the user to TaxRock to log in and consent. TaxRock redirects back to
your app with an authorization code.
2
Your backend gets tokens
Exchange the code for a long-lived refresh token and a short-lived
access token. Store the refresh token securely, per end-user.
3
You call the API
Send the access token as a
Bearer credential. When it expires (~1 hour),
exchange the refresh token for a new one.Sandbox vs. production
Everything defaults to the sandbox while you build. Two base URLs change between environments. Theaudience is the same in both.

