{"openapi":"3.0.1","info":{"title":"Check Cherry App Credentials (Legacy)","version":"v1","description":"This page covers the original way an app authenticated to a customer's account: a\nsingle `App ID` and `App Secret` pair, sent with every request along with the ID of\nthe customer you are acting for.\n\n**Most apps should use OAuth instead.** New apps are set up on OAuth from the start;\nthe flow is in the\n[App Platform guide](/api/docs?spec=app). If your app already runs on App ID and App\nSecret, it keeps working, and the last section below covers moving over.\n\n## Authentication\n\nYour App ID and App Secret are on your app's page in the\n[developer portal](https://www.checkcherry.com/developer/apps). Send them as headers\non every request, together with the customer's Check Cherry account ID as\n`FRANCHISE-ID`:\n\n```\ncurl -H \"App-ID: <app id>\"      -H \"App-Secret: <app secret>\"      -H \"FRANCHISE-ID: <customer's account id>\"      https://api.checkcherry.com/api/v1/leads\n```\n\nAll three are also accepted as query parameters (`app_id`, `app_secret`,\n`franchise_id`). Prefer headers; query strings end up in logs.\n\n**Which accounts you can act for.** Only accounts that have enabled your app from\ntheir Integrations page. A `FRANCHISE-ID` for any other account resolves to nothing\nand the request fails as unauthorized.\n\n**Finding a customer's account ID.** You receive it when they enable your app: it is\nthe `{{franchise_id}}` substitution available to your app's authentication endpoint\nand widget HTML, and every webhook payload carries it as `franchise_id`.\n\n**What the credential can do.** A fixed set of permissions, the same for every app\nand every account. It covers leads, proposals and bookings, appointments, expenses,\navailability, messaging, users, media, offerings, reports, and design templates. It\nis deliberately broad, which is one of the reasons to prefer OAuth: an OAuth app\ndeclares exactly what it needs and nothing more.\n\n**Requests and responses** are the same as for any other credential. See the\n[Business API reference](/api/docs) for every endpoint, the JSON:API response\nformat, pagination, and rate limits.\n\n## Moving to OAuth\n\nYour app can support both credentials at once, so there is no cut-over day.\n\n1. Open your app's **OAuth** page in the developer portal, enable OAuth, and declare\n   the permissions your app actually uses. Set an Install URL.\n2. Implement the authorization flow from the [App Platform guide](/api/docs?spec=app).\n   Store the tokens you receive per customer.\n3. For each request, use the customer's OAuth token if you hold one; otherwise fall\n   back to App ID and App Secret.\n4. Ask existing customers to connect through your Install URL. Each one who does gets\n   their own token and appears on their Integrations page as an installed app.\n\nNothing in Check Cherry needs to change on the customer's side beyond that one\nauthorization. Their existing enablement of your app stays in place, so requests\nthat still use App ID and App Secret continue to work while you migrate.\n"},"paths":{},"servers":[{"url":"https://api.checkcherry.com"}],"components":{"securitySchemes":{"app_id":{"type":"apiKey","name":"App-ID","in":"header","description":"Your App ID from the developer portal"},"app_secret":{"type":"apiKey","name":"App-Secret","in":"header","description":"Your App Secret from the developer portal"},"franchise_id":{"type":"apiKey","name":"FRANCHISE-ID","in":"header","description":"The customer's Check Cherry account ID"}}}}