v1

latestOpenAPI 3.0.02026-07-241220330.3 KB
OAuth

Generate a new OAuth bearer token from the given client credentials.

Application token and application secret MUST be provided, either as properties in the JSON body, or in the Authorization header.

The returned bearer token will allow the client all the same access permissions as the given application token and secret. Bearer tokens are sent in the Authorization header in the form Bearer <bearer_token>.

All bearer tokens expire one hour from generation.

post/oauth/bearer

Headers

Authorizationstring

Basic authorization header per the OAuth Client Authorization Header standard.

The format is Basic <auth_string>, where <auth_string> is the base64 encoding of the string application_token:application_secret (the application token and application secret, separated by a colon character).

Request body

application_tokenstring

Application token for the client. This is the application token for a particular workflow.

application_secretstring

Application secret for the client. This is the application secret for a particular workflow (and must match the application token).

grant_type'client_credentials'

OAuth grant type. Only the "Client Credentials" grant type is supported.

Response

The generated OAuth bearer token.

If credentials are sent in the Authorization header, the OAuth standard fields access_token, token_type, and expires_in are returned.

If credentials are sent in the JSON body, fields bearer_token and expires are returned. This is for backwards-compatibility with the original version of this API.

access_tokenstring

OAuth bearer token in JWT format.

bearer_tokenstring

OAuth bearer token.

token_type'bearer'
expires_innumber

Seconds until expiration.

expiresnumber

Expiration time, in milliseconds past the epoch.