Navexa API
    • Start your Navexa journey
    • Authentication
    • Navexa MCP
    • Rate limits
    • Reports
      • Get ATO myTax report
        GET
      • Get ATO myTax report PDF
        GET
      • Get Capital Gains Tax report
        GET
      • List capital losses
        GET
      • Get tax overview for a period
        GET
      • List tax years
        GET
      • Get tax year status
        GET
      • Get Taxable Income report
        GET
      • Get tax readiness
        GET
      • Get Unrealised Capital Gains Tax report
        GET
    • Benchmark
      • Get the benchmark return for a portfolio
        GET
    • CashAccount
      • Get Cash Account
        GET
      • Delete a Cash Account
        DELETE
      • Get all Cash Accounts
        GET
      • Create a Cash Account
        POST
      • Update a Cash Account
        PUT
      • Get Cash Account Transactions
        GET
    • CashAccountTransactions
      • Get a Cash Account Transaction
        GET
      • Delete a Cash Account Transaction
        DELETE
      • Create a Cash Account Transaction
        POST
      • Update a Cash Account Transaction
        PUT
    • Clients
      • Get all Clients
      • Create a client
      • Gets Client
      • Update a client
      • Delete client
      • Get client Portfolios
      • Assign portfolios to client
    • Holdings
      • Get a holding
      • Update a holding
      • Delete a holding
      • Get a holding's trades
      • Get holding income records
      • Update a holding's symbol and exchange
    • PortfolioPerformance
      • Get portfolio performance
    • Portfolios
      • Get return contribution by holding
      • Get portfolio diversification
      • Get portfolio income calendar
      • Get portfolio return broken down by group
      • Get all portfolios
      • Create a portfolio
      • Get all portfolios, grouped
      • Get a portfolio
      • Update a portfolio
      • Delete a portfolio
      • Get all portfolio holdings
    • ProRataDistributions
      • Update ETF Distributions ProRata
    • StocksIncome
      • Add income to a holding
      • Get an income record
      • Update Income record
      • Delete an income record
      • Confirm Income record
    • TaxSettings
      • Get all portfolio tax settings
      • Get portfolio tax setting
      • Update portfolio tax settings
    • Trades
      • Get a trade
      • Update a trade
      • Delete a trade
      • Add a trade
      • Upload a trade attachment
      • Download a trade attachment
    • CustomInvestmentPrice
      • List Prices
      • Add a Price
      • Update a Price
      • Get a Price
      • Delete a Price
      • Bulk Add Prices
    • SimulateSell
      • Get the assessable capital gain for a simulated sell trade
    • Sources
      • Get all sources
    • HoldingTimeseries
      • Get holding timeseries
    • PortfolioTimeseries
      • Get portfolio timeseries
    • PortfolioTransactions
      • Get portfolio transactions
    • Securities
      • Search securities
    • CustomGroups
      • List custom groups
      • Create a custom group
      • Get a custom group
      • Update a custom group
      • Delete a custom group
      • List custom group assignments
      • Set custom group assignments
    • Account
      • Get account
      • List plan features
      • Get portfolio limits
    • Schemas
      • Sample Schemas
        • Pet
        • Category
        • Tag
      • Schemas
        • AccountLinkSettings
        • AccountSettings
        • AccountLinkViewModel
        • AddClientVM
        • AddTradeModel
        • AddPriceModel
        • AddClientModel
        • ApplicationUser
        • AuthorizeTokenRequest
        • BenchmarkSettings
        • CalculationSettings
        • AdjustmentData
        • CategoryPerformancePreferenceOptions
        • ChartPreferenceOptions
        • AssignPortfolioToClientVM
        • ChecklistItem
        • Client
        • AutomationSettings
        • ClientExpanded
        • CGTDistributionsModel
        • BillingSettings
        • ClientModel
        • CGTError
        • ClientPortfolio
        • CGTEventModel
        • ClientVM
        • CGTReportModel
        • ColumnSettings
        • ComponentColumn
        • CapitalGainLoss
        • ComponentSettings
        • CapitalGainsBreakdown
        • CreateCashAccountVM
        • CapitalGainsTaxSummary
        • CreateCashTransactionVM
        • CapitalGainsTaxSummaryModel
        • CreateComponentDTO
        • CashInterest
        • CreatePortfolioSettingsModel
        • CryptoIncome
        • CryptoTrade2
        • CustomGroupCategory
        • DiversificationPreferenceOptions
        • Dividend
        • ClientPortfolioVM
        • DividendDTO
        • DividendError
        • EmailSettings
        • EmbeddedComponent
        • FilterCriteria
        • CompanyListResponseDTO
        • GroupAccount
        • CompanyManagementDTO
        • GroupAccountResponse
        • GetPriceModel
        • GroupUserAdd
        • GroupUserLookup
        • CreateProPortfolioVM
        • GroupUserResponse
        • GroupUserUpdate
        • CryptoIncomeDTO
        • Holding
        • CryptoIncomeSummary
        • HoldingClassification
        • HoldingModel
        • HoldingNote
        • DateRange
        • HoldingPerformancePreferenceOptions
        • DeductionsSummary
        • HoldingPublisherData
        • HoldingSettingsModel
        • CryptocurrencyListResponseDTO
        • HoldingTaxSettings
        • CryptocurrencyManagementDTO
        • HoldingType
        • DividendData
        • IHoldingSettings
        • CustomerProfileDto
        • IncomeContributionsSettings
        • CustomerSearchResultDto
        • IncomeReturnPreferenceOptions
        • IntegrationMethodAccuracy
        • IntegrationMethodSupportLevel
        • ForeignTaxableIncomeSummary
        • IntegrationType
        • IntercomSettings
        • IosIapPurchase
        • IosIapSubscriptionInfo
        • ManageClientModel
        • Metadata
        • OnboardingChecklist
        • OnboardingSurvey
        • OverviewPreferences
        • OwnerPlan
        • GicIndustry
        • PaymentPlatform
        • GicIndustryGroup
        • Portfolio
        • GicSector
        • PortfolioDiviersifcationSettings
        • GicSubIndustry
        • PortfolioPreferences
        • HoldingReturnViewModel
        • PortfolioRequest
        • PortfolioSettings
        • PortfolioHoldingModel
        • HoldingSummaryPerformanceViewModel
        • PortfolioTaxSetting
        • PortfolioModel
        • PortfolioType
        • HoldingTaxSettingsVM
        • HoldingSymbolUpdateModel
        • ProRataTotals
        • HoldingTaxSettingsDTO
        • ProRegisterModel
        • HoldingTypeEnum
        • Provider
        • ProviderIntegrationMethod
        • SaleAllocationStrategies
        • IncomeIntegrationMapping
        • SharingSettings
        • IncomeIntegrationMappingDto
        • SubscriptionPlan
        • IncomeRecord
        • ImpersonationRequestDto
        • TestimonialInformation
        • ImpersonationResponseDto
        • TimeSpan
        • TrackingInformation
        • Trade
        • TradeMetadata
        • TradeType
        • InterestIncomeSummary
        • TradeTypeEnum
        • UpdateCashAccountVM
        • UpdateCashTransactionVM
        • UpsertIncomeRecord
        • IntercomAdmin
        • UpsertPortfolioModel
        • UpdatePriceModel
        • MyTaxIncomeSummary
        • IntercomAvatar
        • UserPortfolio
        • MyTaxReportModel
        • IntercomCanvasContext
        • UserPreferences
        • IntercomCanvasInitializeDto
        • UserSharedWith
        • IntercomCanvasSubmitDto
        • IntercomContact
        • IntercomCustomer
        • IntercomRevokeAccessDto
        • PortfolioPerformanceViewModel
        • PortfolioTaxSettingDTO
        • PortfolioTaxSettingsVM
        • SharePortfoliosVM
        • NotificationSettings
        • TaxableIncomeReportModel
        • TaxableIncomeSummary
        • TotalReturnViewModel
        • TradeIntegrationMapping
        • StartImpersonationDto
        • StopImpersonationDto
        • TrialEligibilityDto
        • TrialResetRequestDto
        • TrialResetResponseDto
        • UpdateAccountSettingsDto
        • UpdateUserProfileDto
      • Navexa.API.Controllers.PublicAPI.AllocationModels.Models.PublicAllocationBucket
      • Navexa.API.Controllers.PublicAPI.CashAccounts.ViewModels.CashTransactionViewModel
      • Navexa.API.Controllers.PublicAPI.Account.Models.AccountAllowances
      • Navexa.API.Controllers.PublicAPI.CashAccounts.ViewModels.CreateCashAccountVM
      • Navexa.API.Controllers.PublicAPI.AllocationModels.Models.PublicAllocationModel
      • Navexa.API.Controllers.PublicAPI.Account.Models.AccountFeature
      • Navexa.API.Controllers.PublicAPI.CashAccounts.ViewModels.CreateCashTransactionVM
      • Navexa.API.Controllers.PublicAPI.AllocationModels.Models.PublicCalculateRebalanceRequest
      • Navexa.API.Controllers.PublicAPI.Account.Models.AccountModel
      • Navexa.API.Controllers.PublicAPI.AllocationModels.Models.PublicCalculateRebalanceResponse
      • Navexa.API.Controllers.PublicAPI.CashAccounts.ViewModels.GetCashAccountVM
      • Navexa.API.Controllers.PublicAPI.Account.Models.AccountPortfolioLimits
      • Navexa.API.Controllers.PublicAPI.CashAccounts.ViewModels.UpdateCashAccountVM
      • Navexa.API.Controllers.PublicAPI.AllocationModels.Models.PublicDriftEntry
      • Navexa.API.Controllers.PublicAPI.CashAccounts.ViewModels.UpdateCashTransactionVM
      • Navexa.API.Controllers.PublicAPI.AllocationModels.Models.PublicDriftReport
      • Navexa.API.Controllers.PublicAPI.Clients.ViewModels.AddClientVM
      • Navexa.API.Controllers.PublicAPI.AllocationModels.Models.PublicRebalanceLeg
      • Navexa.API.Controllers.PublicAPI.Clients.ViewModels.ClientPortfolioVM
      • Navexa.API.Controllers.PublicAPI.Clients.ViewModels.ClientVM
      • Navexa.API.Controllers.PublicAPI.CustomGroups.Models.CustomGroupAssignmentModel
      • Navexa.API.Controllers.PublicAPI.CustomGroups.Models.CustomGroupModel
      • Navexa.API.Controllers.PublicAPI.CustomGroups.Models.GroupCategoryModel
      • Navexa.API.Controllers.PublicAPI.CustomGroups.Models.HoldingGroupAssignmentModel
      • Navexa.API.Controllers.PublicAPI.CustomGroups.Models.UpsertCustomGroupModel
      • Navexa.API.Controllers.PublicAPI.CustomInvestments.Models.AddPriceModel
      • Navexa.API.Controllers.PublicAPI.CustomInvestments.Models.BulkAddPricesModel
      • Navexa.API.Controllers.PublicAPI.CustomInvestments.Models.BulkPriceEntry
      • Navexa.API.Controllers.PublicAPI.CustomInvestments.Models.GetPriceModel
      • Navexa.API.Controllers.PublicAPI.CustomInvestments.Models.UpdatePriceModel
      • Navexa.API.Controllers.PublicAPI.Holdings.Models.HoldingIncomeModel
      • Navexa.API.Controllers.PublicAPI.Holdings.Models.HoldingModel
      • Navexa.API.Controllers.PublicAPI.Holdings.Models.HoldingSettingsModel
      • Navexa.API.Controllers.PublicAPI.Holdings.Models.HoldingSymbolUpdateModel
      • Navexa.API.Controllers.PublicAPI.Holdings.Models.HoldingTimeseriesRequest
      • Navexa.API.Controllers.PublicAPI.Holdings.Models.HoldingTradeModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.CreatePortfolioSettingsModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.DeletePortfolioResponse
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.HoldingReturnViewModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.HoldingSummaryPerformanceViewModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioHoldingModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioPerformanceViewModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioTimeseriesRequest
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioTransactionsRequest
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioAutomationSettingsModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioTransactionsResponse
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioBenchmarkSettingsModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.SimulateSellRequest
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioCalculationSettingsModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.SimulateSellResponse
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioContributionRequest
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.UpsertPortfolioModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.Transactions.TransactionCryptoIncomeModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioDiversificationRequest
      • Navexa.API.Controllers.PublicAPI.ProRataDistributions.Models.ProRataTotals
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.Transactions.TransactionDividendModel
      • Navexa.API.Controllers.PublicAPI.Securities.Models.SecuritySearchResultModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.Transactions.TransactionHoldingModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioIncomeCalendarRequest
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.Transactions.TransactionLegModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioListResponse
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.Transactions.TransactionLinkModel
      • Navexa.API.Controllers.PublicAPI.Shared.Models.TimeseriesRange
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.Transactions.TransactionModel
      • Navexa.API.Controllers.PublicAPI.Shared.Models.TimeseriesResponse
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.Transactions.TransactionSourceModel
      • Navexa.API.Controllers.PublicAPI.Portfolios.Models.PortfolioSettingsModel
      • Navexa.API.Controllers.PublicAPI.Shared.Models.TimeseriesSummary
      • Navexa.API.Controllers.PublicAPI.Sources.Models.SourceModel
      • Navexa.API.Controllers.PublicAPI.StocksIncome.Models.CreateHoldingIncomeModel
      • Navexa.API.Controllers.PublicAPI.Shared.Models.TimeseriesMeta
      • Navexa.API.Controllers.PublicAPI.StocksIncome.Models.CryptoIncomeRecord
      • Navexa.API.Controllers.PublicAPI.StocksIncome.Models.IncomeRecord
      • Navexa.API.Controllers.PublicAPI.Shared.Models.TimeseriesPoint
      • Navexa.API.Controllers.PublicAPI.StocksIncome.Models.UpsertCryptoIncomeModel
      • Navexa.API.Controllers.PublicAPI.StocksIncome.Models.UpsertIncomeRecord
      • Navexa.API.Controllers.PublicAPI.TaxReports.Models.CGTDistributionsModel
      • Navexa.API.Controllers.PublicAPI.TaxReports.Models.CGTReportModel
      • Navexa.API.Controllers.PublicAPI.TaxReports.Models.TaxableIncomeReportModel
      • Navexa.API.Controllers.PublicAPI.TaxSettings.Models.HoldingTaxSettingsDTO
      • Navexa.API.Controllers.PublicAPI.TaxSettings.Models.PortfolioTaxSettingDTO
      • Navexa.API.Controllers.PublicAPI.TaxReports.Models.CGTEventModel
      • Navexa.API.Controllers.PublicAPI.Trades.Models.TradeModel
      • Navexa.API.Controllers.PublicAPI.TaxReports.Models.CapitalGainsTaxSummaryModel
      • Navexa.API.Controllers.Reports.TaxReports.CapitalGainsTaxReport.Models.HoldingTaxSettingsVM
      • Navexa.API.Controllers.Reports.TaxReports.CapitalGainsTaxReport.Models.PortfolioTaxSettingsVM
      • Navexa.API.DTOs.CryptoIncomeDTO
      • Navexa.API.ViewModels.AccountLinkViewModel
      • Navexa.API.Controllers.PublicAPI.Trades.Models.AddTradeModel
      • Navexa.API.ViewModels.BenchmarkReturnViewModel
      • Navexa.API.ViewModels.TotalReturnViewModel
      • Navexa.Core.DomainModels.CGTError
      • Navexa.API.Controllers.PublicAPI.Trades.Models.UpdateTradeModel
      • Navexa.Core.DomainModels.CapitalGainLoss
      • Navexa.Core.DomainModels.CapitalGainsBreakdown
      • Navexa.Core.DomainModels.CryptoIncomeSummary
      • Navexa.Core.DomainModels.DateRange
      • Navexa.Core.DomainModels.DeductionsSummary
      • Navexa.Core.DomainModels.ForeignTaxableIncomeSummary
      • Navexa.API.Controllers.PublicAPI.TaxReports.Models.PortfolioCapitalLossApplicationModel
      • Navexa.Core.DomainModels.InterestIncomeSummary
      • Navexa.API.Controllers.PublicAPI.TaxReports.Models.PortfolioCapitalLossModel
      • Navexa.Core.DomainModels.MyTaxIncomeSummary
      • Navexa.Core.DomainModels.CapitalGainsTaxSummary
      • Navexa.Core.DomainModels.MyTaxReportModel
      • Navexa.Core.DomainModels.TaxableIncomeSummary
      • Navexa.Core.DomainModels.TotalReturn
      • Navexa.Core.Enums.AMITDataSource
      • Navexa.Core.Enums.HoldingTypeEnum
      • Navexa.Core.Enums.TaxYearLockDriftStatus
      • Navexa.Core.Enums.TaxYearLockMode
      • Navexa.Core.Models.HoldingClassification
      • Navexa.Core.Services.PortfolioFilter.Models.FilterCriteria
      • Navexa.API.Filters.PlanFeatureRoute
      • Navexa.Core.Services.PortfolioFilter.Models.TransactionFilterItem
      • Navexa.Core.Services.TaxServices.TaxReports.TaxableIncome.Models.CashInterest
      • Navexa.Core.DomainModels.AMITReadinessDetail
      • Navexa.Core.Services.AllTransactionsReport.Models.TransactionFilterItem
      • Navexa.Core.Services.AllTransactionsReport.Models.TransactionFiltersRequest
      • Navexa.Core.DomainModels.CapitalGainsSummary
      • Navexa.Core.Services.PortfolioFilter.Models.FilterNode
      • Navexa.Core.DomainModels.Charting.ChartingDataPoint
      • Navexa.Core.DomainModels.Charting.ContributionChartData
      • Navexa.Core.DomainModels.Charting.ContributionDataPoint
      • Navexa.Core.DomainModels.Charting.DiversificationChartData
      • Navexa.Core.DomainModels.Charting.GroupedHoldingReturn
      • Navexa.Core.DomainModels.Charting.WeightedHolding
      • Navexa.Core.DomainModels.CurrentYearReadiness
      • Navexa.Core.DomainModels.FinancialYearStatus
      • Navexa.Core.DomainModels.FinancialYearSummary
      • Navexa.Core.DomainModels.HistoryReadiness
      • Navexa.Core.DomainModels.HoldingReturn
      • Navexa.Core.DomainModels.IncomeSummary
      • Navexa.Core.DomainModels.InvalidHoldingItem
      • Navexa.Core.DomainModels.Quote
      • Navexa.Core.DomainModels.ReadinessDetail
      • Navexa.Core.DomainModels.ReadinessStatus
      • Navexa.Core.DomainModels.TaxOverviewAllYearsResult
      • Navexa.Core.DomainModels.TaxOverviewResult
      • Navexa.Core.DomainModels.TaxOverviewStatusResult
      • Navexa.Core.DomainModels.TaxReadiness
      • Navexa.Core.DomainModels.TaxReadinessV2Result
      • Navexa.Core.DomainModels.TaxSettings
      • Navexa.Core.DomainModels.TotalPortfolioReturn
      • Navexa.Core.DomainModels.UnfinalisedAMITHolding
      • Navexa.Core.DomainModels.YearToConfirm
      • Navexa.Core.Services.Reports.IncomeCalendarService.Models.IncomeCalendarRecord
      • Navexa.Core.Services.Reports.IncomeCalendarService.Models.IncomeCalendarReport

    Authentication

    Authenticating with the Navexa API#

    The Navexa API supports two authentication methods:
    1.
    OAuth 2.0 Authorization Code Flow with PKCE — for applications that act on behalf of a Navexa user.
    2.
    API Key Authentication — for accessing only your own data with a simpler mechanism.

    1. OAuth 2.0 Authorization Code Flow with PKCE#

    Use OAuth 2.0 when your application needs to act on behalf of a Navexa user and access their data with their consent.
    The Navexa OAuth flow requires PKCE (Proof Key for Code Exchange) for all applications, including confidential server-side clients. PKCE protects the authorization code from interception, even if your client_secret is compromised. Most OAuth client libraries (openid-client for Node, Authlib for Python, IdentityModel.OidcClient for .NET, etc.) support PKCE with a single configuration flag.

    Before you start#

    Navexa engineers set up every OAuth application by hand. Email help@navexa.com with the subject API Access Request and include:
    Your company and application name
    What your application does with Navexa data
    The scopes you need
    Your redirect URIs
    We reply with your Client ID, your Client Secret and the scopes approved for your application. Email the same address to change your scopes or redirect URIs later.

    Step 1 — Generate PKCE values#

    Before redirecting the user, generate a PKCE pair on your server:
    code_verifier — a cryptographically random string, 43–128 characters from the URL-safe alphabet (A-Z, a-z, 0-9, -, ., _, ~). Store it in the user's session, keyed by state, so you can retrieve it during the token exchange.
    code_challenge — BASE64URL(SHA256(code_verifier)). This is sent in the authorize request; the raw verifier never leaves your server until step 3.
    Example (Node.js):
    Note: use base64url encoding (URL-safe alphabet, no = padding) — not standard Base64.

    Step 2 — Redirect the user to the authorization endpoint#

    https://auth.navexa.io/authorize?
      response_type=code&
      client_id=YOUR_CLIENT_ID&
      redirect_uri=YOUR_REDIRECT_URI&
      audience=https://api.navexa.io/api&
      scope=openid%20profile%20email%20offline_access%20portfolios:read%20holdings:read%20transactions:read&
      state=RANDOM_STRING&
      code_challenge=YOUR_CODE_CHALLENGE&
      code_challenge_method=S256
    ParameterRequiredDescription
    response_typeYesMust be code.
    client_idYesThe Client ID issued to your application.
    redirect_uriYesMust exactly match a redirect URI registered for your application.
    audienceYesMust be https://api.navexa.io/api. This is the Auth0 identifier for the Navexa API — not a URL you call. (The actual API base URL is https://api.navexa.com.au/api.) Without this parameter, the access token will not be accepted by the API and calls will return 401 Unauthorized.
    scopeYesSpace-separated list: the OpenID Connect scopes plus the Navexa scopes your application needs. Must include offline_access if you want a refresh token.
    stateRecommendedA random, unguessable string. Verify it matches when the user is redirected back, to prevent CSRF.
    code_challengeYesThe PKCE challenge from Step 1.
    code_challenge_methodYesMust be S256. The plain method is not supported.
    The user signs in and sees a consent screen that lists the scopes you requested. After they approve, Auth0 redirects to your redirect_uri with code and state query parameters.

    Step 3 — Exchange the authorization code for tokens#

    Look up the code_verifier you stored in the user's session in Step 1, then send it alongside the rest of the token request:
    curl --request POST \
      --url https://auth.navexa.io/oauth/token \
      --header 'content-type: application/json' \
      --data '{
        "grant_type": "authorization_code",
        "client_id": "YOUR_CLIENT_ID",
        "client_secret": "YOUR_CLIENT_SECRET",
        "code": "AUTHORIZATION_CODE",
        "redirect_uri": "YOUR_REDIRECT_URI",
        "code_verifier": "YOUR_CODE_VERIFIER"
      }'
    code_verifier must be the original random string from Step 1 — not the hashed challenge. Auth0 hashes the verifier itself and compares it to the stored challenge.
    Successful response (HTTP 200):
    {
      "access_token": "eyJhbGciOi...",
      "refresh_token": "v1.Mr...",
      "id_token": "eyJhbGciOi...",
      "token_type": "Bearer",
      "expires_in": 86400,
      "scope": "openid profile email offline_access portfolios:read holdings:read transactions:read"
    }
    refresh_token is only returned if offline_access was requested. id_token is only returned if openid was requested. scope lists what the user approved.

    Step 4 — Call the Navexa API#

    The Navexa API base URL is https://api.navexa.com.au/api. Send the access token in the Authorization header:
    curl --request GET \
      --url https://api.navexa.com.au/api/some-endpoint \
      --header "Authorization: Bearer YOUR_ACCESS_TOKEN"

    Refreshing an access token#

    Access tokens expire — 24 hours for native/server applications, 2 hours for web applications. If you requested offline_access you will have a refresh token — use it to get a new access token without user interaction:
    curl --request POST \
      --url https://auth.navexa.io/oauth/token \
      --header 'content-type: application/json' \
      --data '{
        "grant_type": "refresh_token",
        "client_id": "YOUR_CLIENT_ID",
        "client_secret": "YOUR_CLIENT_SECRET",
        "refresh_token": "YOUR_REFRESH_TOKEN"
      }'
    PKCE parameters are not required on the refresh request — they only apply to the initial authorization code exchange.
    The response shape matches Step 3, with the same scopes the user approved. If refresh-token rotation is enabled for your application, the previous refresh token is invalidated and you must store the new one returned in the response.
    If the refresh token has been revoked or expired, you'll receive invalid_grant and the user will need to re-authorize via Step 2.

    Scopes#

    Scopes say what your application may do with a user's Navexa data. Request only what your application uses. To add a scope later, send the user through Step 2 again with the new list.
    OpenID Connect scopes#
    ScopePurpose
    openidRequired for OpenID Connect — returns an id_token.
    profileBasic profile claims (name, etc.) on the id_token.
    emailEmail and email-verified claims on the id_token.
    offline_accessIssues a refresh_token so you can refresh access tokens without user interaction.
    Navexa scopes#
    ScopeLets your application
    account:readSee the user's plan and account limits
    portfolios:readSee portfolios and custom groups
    portfolios:createCreate portfolios
    portfolios:writeCreate, change and delete portfolios and custom groups
    holdings:readSee holdings and custom prices
    holdings:writeChange and delete holdings and custom prices
    transactions:readSee trades, income and cash transactions
    transactions:writeAdd, change and delete trades, income and cash transactions
    tax:readSee tax reports, tax settings and sale scenarios
    tax:writeChange tax settings and saved sale scenarios
    performance:readSee performance, benchmark, diversification and income reports
    clients:readSee advice clients
    clients:writeAdd, change and delete advice clients
    A write scope does not include its read scope. portfolios:write does include portfolios:create.
    Each endpoint's page lists the scope it needs and the plans it is available on.
    What your application can reach#
    An endpoint works when its scope is approved by both:
    1.
    The user, on the consent screen.
    2.
    Navexa, for your application. To change this, email help@navexa.com with your Client ID.
    The user's plan still applies. A scope does not unlock a feature their plan does not include.

    Error responses#

    Errors from /authorize and /oauth/token follow the OAuth 2.0 standard shape:
    {
      "error": "invalid_grant",
      "error_description": "Authorization code expired"
    }
    Common values: invalid_request, invalid_client, invalid_grant, unauthorized_client, unsupported_grant_type, invalid_scope, access_denied.
    If PKCE values are missing or don't match, you will see one of:
    invalid_request — "The PKCE protocol extension is required." (no code_challenge was sent on /authorize).
    invalid_grant — "Failed to verify code_verifier." (the verifier sent on /oauth/token doesn't match the challenge from /authorize).
    When the API refuses a call#
    A call your application is not allowed to make returns 403 Forbidden and changes nothing:
    {
      "error": "scope_not_granted",
      "message": "The customer did not grant this app the scope this endpoint requires.",
      "requiredScope": "transactions:write"
    }
    errorMeaningWhat to do
    scope_not_grantedrequiredScope is not approved for your applicationRequest it and send the user through Step 2
    connection_revokedThe user disconnected your applicationSend the user through Step 2 again
    client_disabledNavexa suspended your applicationEmail help@navexa.com
    partner_access_errorNavexa could not check accessRetry with backoff
    Users manage linked applications under Settings → Integrations → Connected Apps.

    Important notes#

    PKCE is required for all clients, including server-side applications that hold a client_secret. Always send code_challenge + code_challenge_method=S256 on /authorize and code_verifier on /oauth/token.
    Always include audience=https://api.navexa.io/api on /authorize requests, otherwise the access token will not be accepted by the Navexa API.
    Request Navexa scopes, not only the OpenID Connect scopes, so the consent screen tells users what your application does.
    Keep the authorization code secret — it is single-use and short-lived (~10 minutes). Never log it or expose it in client-side code.
    Keep the client_secret on the server. Native and single-page apps that cannot store a secret should still use this flow with PKCE, simply omitting client_secret from the token request.
    Validate state on the redirect back to your redirect_uri to prevent CSRF.

    When to use OAuth 2.0#

    You need to act on behalf of a Navexa user.
    You're integrating Navexa into a third-party web or mobile application.
    You need user-consented access to resources.

    2. API Key Authentication#

    If you only need to access your own data, you can use an API Key instead of OAuth 2.0.
    Generate an API Key from your account settings.

    Using an API Key#

    Include your API Key in the x-api-key header:
    curl --request GET \
      --url https://api.navexa.com.au/api/some-endpoint \
      --header "x-api-key: YOUR_API_KEY"

    Important notes#

    API Keys grant access only to your own data.
    Scopes do not apply to API Keys.
    API Keys do not expire — treat them like passwords. Rotate them if you suspect exposure.
    Never commit API Keys to source control or expose them in client-side code.

    When to use API Key Authentication#

    You're only accessing your own account's data.
    You're writing personal automation or scripts.
    You don't want to handle token refresh.
    Modified at 2026-09-17 06:17:47
    Previous
    Start your Navexa journey
    Next
    Navexa MCP
    Built with