Getting started
OAuth API
Build apps that work with other people's LifeBots bots. A user clicks “Connect with LifeBots”, approves what your app may do, and your app gets a token to act on their bots — without ever seeing their password, bot secret or API key.
Which API should I use?
| OAuth API (this page) | HTTP API | |
|---|---|---|
| Built for | Apps that serve many LifeBots users | Controlling your own bots |
| Sign-in | The user approves your app once | You paste your API key and bot secret |
| Access | Only the scopes the user approved; they can revoke any time | Everything the key allows |
| Style | REST + JSON | One URL, action= parameter |
Only automating your own bots? The HTTP API is quicker to set up.
How it works
- Register your app once, choosing the scopes it needs. Register an app →
- Send the user to LifeBots to sign in and approve those scopes.
- Swap the returned code for an access token from your app. Authorization flow →
- Call the API with the token: list the user's bots, make them talk, move, moderate groups, and get their events by webhook. Making requests →
What you can do
Bots | List bots, read status and location, log them in and out. |
Chat | IMs, local chat, group chat and notices, dialog replies. |
Movement | Teleport, walk, fly, sit, stand. |
Groups | Invite, eject and set roles in any group the bot is in. |
Inventory | List, give and accept items; wear outfits. |
Estate | Kick, ban, restart and broadcast, for estate-manager bots. |
Money | Read the balance and pay avatars. |
Webhooks | Receive IMs, invites, payments and more as they happen. |
Base URLs
| Authorize (user's browser) | https://lifebots.cloud/oauth/authorize |
| Token | https://api.lifebots.cloud/api/v1/oauth/token |
| API | https://api.lifebots.cloud/api/v1 |
Good to know
- Bots, avatars, groups, roles and items are identified by Second Life UUIDs (
xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx). A bot's id is its avatar UUID. - Commands are carried out by the bot inside Second Life, so the bot must be online. Check
data.resultas well assuccess. - The user who approves must have a verified LifeBots account and be in their own account (not switched into another account they manage).
- Users can revoke your app at any time from their Account Settings; your token then stops working.
Use the menu on the left, or start typing to filter. Every endpoint has its own page with parameters, cURL and JavaScript examples, and an example response.