{
    "item": [
        {
            "name": "Tokens",
            "description": "Logging a member in and out, and renewing the tokens (OAuth 2.1)",
            "item": [
                {
                    "name": "Send the member to log in for the app (OAuth 2.1, the authorization code flow with PKCE)",
                    "request": {
                        "name": "Send the member to log in for the app (OAuth 2.1, the authorization code flow with PKCE)",
                        "description": {
                            "content": "The authorization endpoint (RFC 6749 section 4.1 with PKCE, RFC 7636, as OAuth 2.1 requires). The app opens this address in the phone's browser (ASWebAuthenticationSession, Custom Tabs; never a WebView). It answers 302 to myWebLog's login page on www.myweblog.se, with the same query string. There the member logs in and allows the app, and the page sends the browser to redirect_uri with code and state (or with error=access_denied when the member cancels). The app then exchanges the code at POST /oauth/token with grant_type=authorization_code. The app never sees the member's password.\n\nBefore it opens the browser, the app makes a code_verifier (43 to 128 random characters of A-Z, a-z, 0-9, - . _ ~) and sends its SHA-256 as code_challenge (base64url, no padding). The code is valid for two minutes and once. redirect_uri must be one of the addresses registered for the client, compared exactly. Standard libraries (AppAuth for iOS and Android and their wrappers) do all of this.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "oauth",
                                "authorize"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required)  (This can only be one of code)",
                                        "type": "text/plain"
                                    },
                                    "key": "response_type",
                                    "value": "code"
                                },
                                {
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) ",
                                        "type": "text/plain"
                                    },
                                    "key": "client_id",
                                    "value": "12"
                                },
                                {
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) One of the app's registered redirect addresses (an https app link, or the app's own scheme)",
                                        "type": "text/plain"
                                    },
                                    "key": "redirect_uri",
                                    "value": "se.flygklubben.app:/oauth"
                                },
                                {
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) BASE64URL(SHA-256(code_verifier))",
                                        "type": "text/plain"
                                    },
                                    "key": "code_challenge",
                                    "value": "E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM"
                                },
                                {
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required)  (This can only be one of S256)",
                                        "type": "text/plain"
                                    },
                                    "key": "code_challenge_method",
                                    "value": "S256"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "Returned unchanged to redirect_uri; the app checks it is its own",
                                        "type": "text/plain"
                                    },
                                    "key": "state",
                                    "value": "af0ifjsldkj"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "The language of the login page, when the app knows the member's. Otherwise the page follows the browser's myWebLog language. (This can only be one of se,gb,no,dk)",
                                        "type": "text/plain"
                                    },
                                    "key": "cl",
                                    "value": "se"
                                }
                            ],
                            "variable": []
                        },
                        "header": [
                            {
                                "key": "Accept",
                                "value": "application/problem+json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "Exchange the code, renew the tokens, or get a client token (OAuth 2.1)",
                    "request": {
                        "name": "Exchange the code, renew the tokens, or get a client token (OAuth 2.1)",
                        "description": {
                            "content": "The token endpoint (RFC 6749, as OAuth 2.1 profiles it). A client with a key sends it in a Basic Authorization header (client_id:key, what most OAuth libraries send), or as the form fields client_id and client_secret. A public client (a native app without a server, which has no key) sends client_id alone. The body is form data (application/x-www-form-urlencoded), not JSON, as the standard says.\n\ngrant_type=authorization_code logs a member in: send the code from GET /oauth/authorize, the redirect_uri the login used, the code_verifier (PKCE) and if you like device_name (shown to the member on My settings next to the app's name). The reply has an access token, valid expires_in seconds (3600), and a refresh token, valid 90 days from its last use. Send the access token with every call as \"Authorization: Bearer <access token>\". When it has expired, the API answers 401 with WWW-Authenticate: Bearer error=\"invalid_token\"; then renew.\n\ngrant_type=refresh_token renews: send the refresh token and get a new access token and a new refresh token. The old refresh token is dead at once. A refresh token also dies when the member ends the login on My settings, changes their password, or when the app gives it up at POST /oauth/revoke; then the member logs in again. Only the client that made the login can renew it.\n\ngrant_type=client_credentials gives an access token for the client alone, good for GET /client only. Not for a public client.\n\nThere is no password grant (OAuth 2.1 removed it): grant_type=password gets unsupported_grant_type. A member's password is typed on myWebLog's login page only; no app, ours included, ever handles it.\n\nWrong client credentials count per IP address (429 with Retry-After). Fetching a token counts as a call of the client. The replies of this endpoint follow the OAuth standard, not the Problem Details form of the other endpoints.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "oauth",
                                "token"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": []
                        },
                        "header": [
                            {
                                "key": "Content-Type",
                                "value": "application/x-www-form-urlencoded"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "POST",
                        "body": {
                            "mode": "urlencoded",
                            "urlencoded": [
                                {
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) ",
                                        "type": "text/plain"
                                    },
                                    "key": "grant_type",
                                    "value": "authorization_code"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "The code the login page gave the app, with grant_type=authorization_code",
                                        "type": "text/plain"
                                    },
                                    "key": "code",
                                    "value": "5b1a..."
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "The redirect_uri the login used, with grant_type=authorization_code",
                                        "type": "text/plain"
                                    },
                                    "key": "redirect_uri",
                                    "value": "se.flygklubben.app:/oauth"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "The PKCE verifier the code_challenge was made from, with grant_type=authorization_code",
                                        "type": "text/plain"
                                    },
                                    "key": "code_verifier",
                                    "value": "dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "With grant_type=authorization_code, optional. What the member sees on My settings next to the app's name, such as the phone model.",
                                        "type": "text/plain"
                                    },
                                    "key": "device_name",
                                    "value": "iPhone 15"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "The refresh token to renew with, with grant_type=refresh_token",
                                        "type": "text/plain"
                                    },
                                    "key": "refresh_token",
                                    "value": "mwlrt_..."
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "The client id. Not needed when the client is sent in a Basic Authorization header. A public client sends it alone.",
                                        "type": "text/plain"
                                    },
                                    "key": "client_id",
                                    "value": "4"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "The client's key. Not needed when the client is sent in a Basic Authorization header. A public client has none.",
                                        "type": "text/plain"
                                    },
                                    "key": "client_secret",
                                    "value": "mwlm1_..."
                                }
                            ]
                        },
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "Log a member out (OAuth 2.0 revocation)",
                    "request": {
                        "name": "Log a member out (OAuth 2.0 revocation)",
                        "description": {
                            "content": "Ends the login the refresh token stands for (RFC 7009): the refresh token and the access tokens fetched with it stop working. The client's credentials are sent as for POST /oauth/token. The reply is 200 also for a token that is unknown or already given up, so an app's logout never fails.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "oauth",
                                "revoke"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": []
                        },
                        "header": [
                            {
                                "key": "Content-Type",
                                "value": "application/x-www-form-urlencoded"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "POST",
                        "body": {
                            "mode": "urlencoded",
                            "urlencoded": [
                                {
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) The refresh token to give up",
                                        "type": "text/plain"
                                    },
                                    "key": "token",
                                    "value": "mwlrt_..."
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "client_id",
                                    "value": "4"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "client_secret",
                                    "value": "mwlm1_..."
                                }
                            ]
                        },
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                }
            ]
        },
        {
            "name": "Client",
            "description": "The app making the request",
            "item": [
                {
                    "name": "The app making the request",
                    "request": {
                        "name": "The app making the request",
                        "description": {
                            "content": "The client the access token belongs to: its rights and the organizations it is limited to. Also the \"does my key work\" call: it is the one endpoint that takes a client's own access token (grant_type=client_credentials).",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "client"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": {
                            "type": "oauth2",
                            "oauth2": [
                                {
                                    "key": "redirect_uri",
                                    "value": "https://api.myweblog.se/mobile/v5/oauth/token"
                                },
                                {
                                    "key": "accessTokenUrl",
                                    "value": "https://api.myweblog.se/mobile/v5/oauth/token"
                                },
                                {
                                    "key": "authUrl",
                                    "value": "https://api.myweblog.se/mobile/v5/oauth/authorize"
                                },
                                {
                                    "key": "grant_type",
                                    "value": "authorization_code"
                                }
                            ]
                        }
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                }
            ]
        },
        {
            "name": "Me",
            "description": "The member who is logged in",
            "item": [
                {
                    "name": "The member who is logged in",
                    "request": {
                        "name": "The member who is logged in",
                        "description": {
                            "content": "Who the member is, their organization and their balance. What Mobile v3 gave as GetUserdata and GetBalance. A locked member may read but not change anything (locked is true).",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "me"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                }
            ]
        },
        {
            "name": "Organization",
            "description": "The member's organization, its settings for the app, and the sun times at its reference airport",
            "item": [
                {
                    "name": "The member's organization",
                    "request": {
                        "name": "The member's organization",
                        "description": {
                            "content": "What an app needs to show times, money and bookings right: the organization's location and time zone, its date format, locale and currency, and its booking rules. What Mobile v3 sent as orgData with every reply. Fetch it once per session.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "organization"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "The organization's settings marked for the app",
                    "request": {
                        "name": "The organization's settings marked for the app",
                        "description": {
                            "content": "The settings the organization has marked \"show in the app\" on the website, each with its value. What Mobile v3 gave as GetOrgSettings. Besides id, value and value_type, each setting carries the website's own fields for it, such as its description.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "organization",
                                "settings"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "Dawn, sunrise, sunset and dusk at the organization's reference airport",
                    "request": {
                        "name": "Dawn, sunrise, sunset and dusk at the organization's reference airport",
                        "description": {
                            "content": "One item per date, from date_from to date_to (today for a month when left out, at most 62 days), each time in UTC and in the organization's time zone. Dawn and dusk are the civil twilights. What Mobile v3 gave with includeSun on GetBookings. A day when the sun does not rise or set has null for that time.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "sun-times"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "date_from",
                                    "value": "2026-06-21"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "date_to",
                                    "value": "2026-06-22"
                                }
                            ],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                }
            ]
        },
        {
            "name": "Objects",
            "description": "Aircraft, equipment and premises the member may see",
            "item": [
                {
                    "name": "The objects the member may see",
                    "request": {
                        "name": "The objects the member may see",
                        "description": {
                            "content": "Aircraft, equipment and premises, the organization's own and the ones shared with it, as the website's booking calendar shows them to this member, in the website's order. What Mobile v3 gave as GetObjects. The picture of an object is its own endpoint, /objects/{id}/thumbnail; has_thumbnail says whether there is one.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "objects"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "How many items to return, 1 to 500 (100 when left out; 20 for transactions)",
                                        "type": "text/plain"
                                    },
                                    "key": "limit",
                                    "value": "50"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "How many items to skip (0 when left out)",
                                        "type": "text/plain"
                                    },
                                    "key": "offset",
                                    "value": "0"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "true to also count all the items that match (meta.total)",
                                        "type": "text/plain"
                                    },
                                    "key": "include_total",
                                    "value": "false"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "Optional blocks to add to each object, separated by commas",
                                        "type": "text/plain"
                                    },
                                    "key": "include",
                                    "value": "status,active_remarks"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "Fields to leave out of each object, separated by commas",
                                        "type": "text/plain"
                                    },
                                    "key": "exclude",
                                    "value": "comment"
                                }
                            ],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "One object",
                    "request": {
                        "name": "One object",
                        "description": [],
                        "url": {
                            "path": [
                                "objects",
                                ":id"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "include",
                                    "value": "status,settings"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "exclude",
                                    "value": "comment"
                                }
                            ],
                            "variable": [
                                {
                                    "type": "any",
                                    "value": "710",
                                    "key": "id",
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) The item's id",
                                        "type": "text/plain"
                                    }
                                }
                            ]
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "The object's picture",
                    "request": {
                        "name": "The object's picture",
                        "description": {
                            "content": "A JPEG, 150 by 100 pixels, as the website shows it. The reply may be kept for a day (Cache-Control) and carries an ETag. 404 with code 10304 when the object has no picture.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "objects",
                                ":id",
                                "thumbnail"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": [
                                {
                                    "type": "any",
                                    "value": "710",
                                    "key": "id",
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) The item's id",
                                        "type": "text/plain"
                                    }
                                }
                            ]
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "image/jpeg"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                }
            ]
        },
        {
            "name": "Bookings",
            "description": "Bookings as the member sees them",
            "item": [
                {
                    "name": "Bookings as the member sees them",
                    "request": {
                        "name": "Bookings as the member sees them",
                        "description": {
                            "content": "The bookings the website's booking calendar shows this member, from date_from (today when left out) to date_to, in the website's order, the ones in the queue last. mine=true gives only the member's own, as booker or as student. Contact details of the booker and the student follow each member's own settings: null when hidden. What Mobile v3 gave as GetBookings. 403 with code 10301 when the organization has switched booking off.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "bookings"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "How many items to return, 1 to 500 (100 when left out; 20 for transactions)",
                                        "type": "text/plain"
                                    },
                                    "key": "limit",
                                    "value": "50"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "How many items to skip (0 when left out)",
                                        "type": "text/plain"
                                    },
                                    "key": "offset",
                                    "value": "0"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "true to also count all the items that match (meta.total)",
                                        "type": "text/plain"
                                    },
                                    "key": "include_total",
                                    "value": "false"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "object_id",
                                    "value": "710"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "mine",
                                    "value": "true"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "date_from",
                                    "value": "2026-10-01"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "date_to",
                                    "value": "2026-10-31"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "exclude",
                                    "value": "student,comment"
                                }
                            ],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "Book an object for the member",
                    "request": {
                        "name": "Book an object for the member",
                        "description": {
                            "content": "A private booking for the member, through the website's booking class: the same rules as the booking calendar (who may book what, overlaps, queue, lengths, balance) and the same messages. What Mobile v3 did as CreateBooking. The times are points in time with their offset or Z; the booking is made in the organization's time zone. 201 with the booking as GET gives it, a Location header, and \"messages\" for the member (information and warnings the website would show). 409 with code 10300 when a rule stops it: \"errors\" has the rule's text, meant for the member. Accept-Language picks the language of the texts (sv, en, nb, da). A locked member gets 403 (10302), an organization with booking switched off 403 (10301).",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "bookings"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "disabled": true,
                                "description": {
                                    "content": "The language of the texts for the member in \"messages\" and in a rule's error, sv, en, nb or da. English when left out.",
                                    "type": "text/plain"
                                },
                                "key": "Accept-Language",
                                "value": "sv"
                            },
                            {
                                "key": "Content-Type",
                                "value": "application/json"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "POST",
                        "body": {
                            "mode": "raw",
                            "raw": "{\n  \"object_id\": 710,\n  \"start_at\": \"2026-10-10T08:00:00Z\",\n  \"end_at\": \"2026-10-10T12:00:00+02:00\",\n  \"comment\": \"Local flight\",\n  \"expected_airborne\": 1.5\n}",
                            "options": {
                                "raw": {
                                    "headerFamily": "json",
                                    "language": "json"
                                }
                            }
                        },
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "End the booking now",
                    "request": {
                        "name": "End the booking now",
                        "description": {
                            "content": "Ends a booking that is going on, now, through the website's booking class. What Mobile v3 did as CutBooking. The booking's permissions.can_cut says beforehand whether the member may. 200 with the booking as it is afterwards and \"messages\"; 409 with code 10300 when a rule stops it.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "bookings",
                                ":id",
                                "cut"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": [
                                {
                                    "type": "any",
                                    "value": "710",
                                    "key": "id",
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) The item's id",
                                        "type": "text/plain"
                                    }
                                }
                            ]
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "disabled": true,
                                "description": {
                                    "content": "The language of the texts for the member in \"messages\" and in a rule's error, sv, en, nb or da. English when left out.",
                                    "type": "text/plain"
                                },
                                "key": "Accept-Language",
                                "value": "sv"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "POST",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "Cancel the booking",
                    "request": {
                        "name": "Cancel the booking",
                        "description": {
                            "content": "Cancels a booking through the website's booking class, which also sends the website's cancellation mails. What Mobile v3 did as DeleteBooking. A reason is required when the organization requires one (booking.cancel_reason_required on /organization); the class says so with 409 otherwise. The booking's permissions.can_cancel says beforehand whether the member may. 200 with the booking as it was, since it is gone afterwards, and \"messages\".",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "bookings",
                                ":id",
                                "cancel"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [],
                            "variable": [
                                {
                                    "type": "any",
                                    "value": "710",
                                    "key": "id",
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) The item's id",
                                        "type": "text/plain"
                                    }
                                }
                            ]
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "disabled": true,
                                "description": {
                                    "content": "The language of the texts for the member in \"messages\" and in a rule's error, sv, en, nb or da. English when left out.",
                                    "type": "text/plain"
                                },
                                "key": "Accept-Language",
                                "value": "sv"
                            },
                            {
                                "key": "Content-Type",
                                "value": "application/json"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "POST",
                        "body": {
                            "mode": "raw",
                            "raw": "{\n  \"reason\": \"Weather\"\n}",
                            "options": {
                                "raw": {
                                    "headerFamily": "json",
                                    "language": "json"
                                }
                            }
                        },
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "One booking",
                    "request": {
                        "name": "One booking",
                        "description": [],
                        "url": {
                            "path": [
                                "bookings",
                                ":id"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "exclude",
                                    "value": "student"
                                }
                            ],
                            "variable": [
                                {
                                    "type": "any",
                                    "value": "710",
                                    "key": "id",
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) The item's id",
                                        "type": "text/plain"
                                    }
                                }
                            ]
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                }
            ]
        },
        {
            "name": "Flight log",
            "description": "The organization's logged flights",
            "item": [
                {
                    "name": "The organization's flight log",
                    "request": {
                        "name": "The organization's flight log",
                        "description": {
                            "content": "The flights logged on the organization's objects and on the objects shared with it, oldest first unless order=desc. mine=true gives the member's own flights, as pilot or as instructor. What Mobile v3 gave as GetFlightLog and GetFlightLogReversed. When the organization hides the pilot in its log, crew_hidden is true and the crew is null, as on the website.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "flightlogs"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "How many items to return, 1 to 500 (100 when left out; 20 for transactions)",
                                        "type": "text/plain"
                                    },
                                    "key": "limit",
                                    "value": "50"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "How many items to skip (0 when left out)",
                                        "type": "text/plain"
                                    },
                                    "key": "offset",
                                    "value": "0"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "true to also count all the items that match (meta.total)",
                                        "type": "text/plain"
                                    },
                                    "key": "include_total",
                                    "value": "false"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "object_id",
                                    "value": "710"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "mine",
                                    "value": "true"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "date_from",
                                    "value": "2026-01-01"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "date_to",
                                    "value": "2026-12-31"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "asc (oldest first, the default) or desc (newest first) (This can only be one of asc,desc)",
                                        "type": "text/plain"
                                    },
                                    "key": "order",
                                    "value": "desc"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "exclude",
                                    "value": "totals"
                                }
                            ],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "One logged flight",
                    "request": {
                        "name": "One logged flight",
                        "description": [],
                        "url": {
                            "path": [
                                "flightlogs",
                                ":id"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "exclude",
                                    "value": "totals"
                                }
                            ],
                            "variable": [
                                {
                                    "type": "any",
                                    "value": "710",
                                    "key": "id",
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) The item's id",
                                        "type": "text/plain"
                                    }
                                }
                            ]
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                }
            ]
        },
        {
            "name": "Transactions",
            "description": "The member's account",
            "item": [
                {
                    "name": "The member's transactions",
                    "request": {
                        "name": "The member's transactions",
                        "description": {
                            "content": "Charges to and payments into the member's account, newest first, from date_from (a year back when left out) to date_to, 20 per page unless limit says otherwise. Each has the balance after it; meta has the balance now and the balance before the oldest transaction on the page. What Mobile v3 gave as GetTransactions.",
                            "type": "text/plain"
                        },
                        "url": {
                            "path": [
                                "transactions"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "How many items to return, 1 to 500 (100 when left out; 20 for transactions)",
                                        "type": "text/plain"
                                    },
                                    "key": "limit",
                                    "value": "50"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "How many items to skip (0 when left out)",
                                        "type": "text/plain"
                                    },
                                    "key": "offset",
                                    "value": "0"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "true to also count all the items that match (meta.total)",
                                        "type": "text/plain"
                                    },
                                    "key": "include_total",
                                    "value": "false"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "date_from",
                                    "value": "2026-01-01"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "date_to",
                                    "value": "2026-12-31"
                                },
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "exclude",
                                    "value": "booked_by"
                                }
                            ],
                            "variable": []
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                },
                {
                    "name": "One transaction",
                    "request": {
                        "name": "One transaction",
                        "description": [],
                        "url": {
                            "path": [
                                "transactions",
                                ":id"
                            ],
                            "host": [
                                "{{baseUrl}}"
                            ],
                            "query": [
                                {
                                    "disabled": true,
                                    "description": {
                                        "content": "",
                                        "type": "text/plain"
                                    },
                                    "key": "exclude",
                                    "value": "booked_by"
                                }
                            ],
                            "variable": [
                                {
                                    "type": "any",
                                    "value": "710",
                                    "key": "id",
                                    "disabled": false,
                                    "description": {
                                        "content": "(Required) The item's id",
                                        "type": "text/plain"
                                    }
                                }
                            ]
                        },
                        "header": [
                            {
                                "disabled": true,
                                "description": {
                                    "content": "Your own id for the request, at most 64 printable characters. It is returned with the reply. If you send none, one is made for you.",
                                    "type": "text/plain"
                                },
                                "key": "Request-Id",
                                "value": "app-2026-10-06-0001"
                            },
                            {
                                "key": "Accept",
                                "value": "application/json"
                            }
                        ],
                        "method": "GET",
                        "body": [],
                        "auth": null
                    },
                    "response": [],
                    "event": [],
                    "protocolProfileBehavior": {
                        "disableBodyPruning": true
                    }
                }
            ]
        }
    ],
    "auth": {
        "type": "oauth2",
        "oauth2": [
            {
                "type": "any",
                "value": "https://api.myweblog.se/mobile/v5/oauth/token",
                "key": "redirect_uri"
            },
            {
                "type": "any",
                "value": "https://api.myweblog.se/mobile/v5/oauth/token",
                "key": "accessTokenUrl"
            },
            {
                "type": "any",
                "value": "https://api.myweblog.se/mobile/v5/oauth/authorize",
                "key": "authUrl"
            },
            {
                "type": "any",
                "value": "authorization_code",
                "key": "grant_type"
            }
        ]
    },
    "event": [],
    "variable": [
        {
            "key": "baseUrl",
            "value": "https://api.myweblog.se/mobile/v5"
        },
        {
            "key": "bearerToken",
            "value": ""
        }
    ],
    "info": {
        "name": "myWebLog Mobile API",
        "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json",
        "description": {
            "content": "The Mobile API of myWebLog, version 5: what an app shows a member of an organization.\n\nTwo things call this API. A client (a developer's app) has a client id, made by myWebLog on request, and a key when it has a server of its own to keep it. A member logs in on myWebLog's own login page, which the app opens in the browser (OAuth 2.1: the authorization code flow with PKCE); the app exchanges the code at POST /oauth/token and gets an access token, valid an hour, and a refresh token, valid 90 days and renewed on use. Every other call carries the access token. The app never sees the member's password. The member sees their app logins on My settings on the website and can end one there.\n\nAn address never ends with a slash. A query parameter that the endpoint does not have gives 400, and so does a field in a JSON body that the endpoint does not have.",
            "type": "text/plain"
        }
    }
}
