Virtual Peaker OAuth Device Discovery (Preferred) API
The OAuth device discovery flow works as follows:1. The device owner fills out an onboarding form on Virtual Peaker's site.2. At the end of the form, we redirect them to the Device Partner's OAuth authorization page via a link.3. The user logs into the Device Partner's app and grants OAuth access permissions.4. The Device Partner app completes OAuth authorization code flow, exchanging the code for an access token.5. Using the access token, the Device Partner calls their API to retrieve the user's devices.6. The Device Partner associates the devices with the correct Virtual Peaker program in their backend.7. The Device Partner handles any additional onboarding logic in their system.8. The Device Partner publishes enrolled device data to Virtual Peaker's API.9. Virtual Peaker discovers devices using the OAuth token provided.10. We subscribe to devices for data publishing and provide a DEVICE_PUBLISH_SECRET.11. Virtual Peaker may optionally pull initial device data from the Device Partner's API.For each utility program, a separate client_id is created.This ID is passed in the OAuth link to associate devices with the correct program.
Virtual Peaker OAuth Device Discovery (Preferred) API is one of 8 APIs that Virtual Peaker publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include OAuth Device Discovery (Preferred). The published artifact set on APIs.io includes an OpenAPI specification, an API reference, API documentation, an engineering blog, and a getting-started guide.
This API exposes 2 operations across 2 paths, and defines 5 schemas. It is described by OpenAPI 3.2.0, at version 2.0.6.
Requests are made against a single base URL, https://example.com.
Metadata
The identity and technical contract details declared by the specification.
Authentication & Security 2
Virtual Peaker OAuth Device Discovery (Preferred) API declares
2 security schemes
for authenticating requests.
It supports OAuth 2.0 (device_partner_api_auth) using the clientCredentials flow, exposing 1 scope.
It supports OAuth 2.0 (device_partner_user_auth) using the authorizationCode flow, exposing 1 scope.
By default, every request must be authenticated.
device_partner_user_auth— If using the OAuth onboarding method, this authentication method is used for the respective endpoints. Please the the FAQ for more details.
Paths & Operations 2
Across 2 paths, the API surfaces 2 operations — 2 GET. Each is listed below with its method, path, parameters, and response codes.
The OAuth device discovery flow works as follows: 1. The device owner fills out an onboarding form on Virtual Peaker's site. 2. At the end of the form, we redirect them to the Dev…
Schemas 5
The contract defines 5 schemas that model the data the API accepts and returns. The most detailed are UserDetails (6 properties), ServiceAddress (6 properties), DeviceDetails (6 properties), Details (1 property). Each schema is shown below with its type and property counts.
Specification
The full machine-readable OpenAPI contract behind this narrative.
Source
More from Virtual Peaker 7
Other APIs Virtual Peaker publishes across the network.
This is an independent, third-party profile of Virtual Peaker OAuth Device Discovery (Preferred) API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.