What changed, and why it matters
This commit is a one-line documentation update. It adds a hyperlink to the interactive authorization flow in the developer API guide. There is no code change, no security fix, and no functional change to the software.
No action required. This is a documentation-only change with no security relevance.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff modifies docs/developers/api/README.md, replacing a plain text phrase with a Markdown link to authentication.md#interactive-authorization. No source code, configuration, or security-sensitive content was changed.
Changed components
docs/developers/api/README.mdInspect captured patch +1 / −1
### docs/developers/api/README.md
@@ -36,7 +36,7 @@ Use `Content-Type: application/json` when sending JSON. Treat non-2xx responses
## Typical payment integration
1. Ask the user for their BTCPay Server URL.
-2. Send them through interactive authorization with only the permissions you need and store scope enabled.
+2. Send them through [interactive authorization flow](authentication.md#interactive-authorization) with only the permissions you need and store scope enabled.
3. Create an invoice from your backend and store the returned invoice ID with your order.
4. Redirect the customer to the returned `checkoutLink`.
5. Register a webhook, retain its secret securely, and verify every delivery against the raw request body.Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.