> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange a Meta OAuth code for a connection

> Completes the Meta (Facebook) Ads connect flow: exchanges the short-lived OAuth `code` returned to your redirect URI for a long-lived access token, looks up the authorizing user's ad accounts, and stores the encrypted token against the first account found. Call it from your OAuth callback page right after the user authorizes in Facebook — you do not need to call `/connect` separately. Owner or admin only.



## OpenAPI

````yaml /openapi.yaml post /api/v1/ads/oauth/exchange
openapi: 3.1.0
info:
  title: Devotel CPaaS API
  description: Orbit by Devotel — Communications Platform as a Service API
  version: 1.0.0
  contact:
    name: Devotel
    url: https://devotel.io
    email: support@devotel.io
  license:
    name: Proprietary
servers:
  - url: https://api.orbit.devotel.io
    description: Production
security:
  - Bearer: []
  - ApiKey: []
tags:
  - name: Messages
    description: >-
      Send and manage messages across all channels (SMS, WhatsApp, RCS, Email,
      Viber, etc.)
  - name: Fax
    description: >-
      List and track fax (MMS/T.38) transmissions on Telnyx-backed fax numbers
      (sending flows through the Messaging API)
  - name: Agents
    description: AI agent creation, configuration, and execution
  - name: Voice
    description: Voice calls, IVR, conferencing, and SIP trunking
  - name: OnCall
    description: On-call rotations and escalation policy planning for incident alerting
  - name: Webhooks
    description: Webhook endpoint management and delivery logs
  - name: Numbers
    description: Phone number search, provisioning, and configuration
  - name: Brand Identity
    description: >-
      Unified cross-channel brand trust posture (10DLC, toll-free, WhatsApp,
      RCS, branded calling, number KYC)
  - name: Contacts
    description: Contact management, segmentation, and lifecycle tracking
  - name: Campaigns
    description: Marketing campaign orchestration and analytics
  - name: Flows
    description: Automation flow builder and execution engine
  - name: Templates
    description: Message template management and approval workflows
  - name: Settings
    description: Organization, channel, and user preference settings
  - name: Verify
    description: OTP generation and verification across channels
  - name: Push
    description: Push notification delivery via FCM and APNs
  - name: Integrations
    description: Third-party service connections and OAuth management
  - name: CDP
    description: >-
      Customer Data Platform — activation surface (CRM object sync, streaming
      destinations, ad-audience activation)
  - name: Files
    description: >-
      Server-to-server media upload, listing, retrieval, and deletion
      (signed-URL backed)
  - name: Commerce
    description: >-
      Omnichannel conversational-commerce — persistent cart + checkout state
      machine, channel-agnostic hosted pay-by-link, native WhatsApp checkout,
      and AP2-style agent payment mandates.
  - name: Sync
    description: >-
      Real-time shared-state primitive (Twilio Sync parity) — Documents, Maps,
      Lists, and ephemeral Streams, with change events relayed over the
      /api/v1/ws/sync WebSocket gateway
  - name: Risk
    description: >-
      Unified cross-channel Trust & Fraud risk scoring — fuses SMS-pumping,
      URL-reputation, Verify Fraud Guard, and Voice Biometrics signals into one
      composite verdict queryable before a send or a call.
  - name: Orby
    description: >-
      In-dashboard Orby operator assistant: streamed assistant turns,
      conversation threads, product knowledge-base search, and the tool-action
      approval gate. Available to signed-in operators only (dashboard session
      auth — API-key requests are rejected).
paths:
  /api/v1/ads/oauth/exchange:
    post:
      tags:
        - Ads
      summary: Exchange a Meta OAuth code for a connection
      description: >-
        Completes the Meta (Facebook) Ads connect flow: exchanges the
        short-lived OAuth `code` returned to your redirect URI for a long-lived
        access token, looks up the authorizing user's ad accounts, and stores
        the encrypted token against the first account found. Call it from your
        OAuth callback page right after the user authorizes in Facebook — you do
        not need to call `/connect` separately. Owner or admin only.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - code
                - redirect_uri
              properties:
                code:
                  type: string
                  description: >-
                    The one-time authorization code Meta appended to your
                    redirect URI.
                redirect_uri:
                  type: string
                  format: uri
                  description: >-
                    The exact HTTPS redirect URI registered with the Meta app
                    and used to obtain the code.
            example:
              code: AQD3xk9d1e2f3g4h5i6j7k8l9m0n
              redirect_uri: https://app.orbit.devotel.io/ads/callback
      responses:
        '200':
          description: >-
            The connected `ad_account_id`, a `connected` flag, and the list of
            `accounts` discovered on the authorizing Meta profile, inside the
            standard `{ data, meta }` envelope.
          content:
            application/json:
              schema:
                type: object
                additionalProperties: true
components:
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Dashboard JWT token from Clerk
    ApiKey:
      type: apiKey
      name: X-API-Key
      in: header
      description: Server-to-server API key (dv_live_sk_*)

````