v1

latestOpenAPI 3.0.12026-07-14217.3 KB
Authentication Service

Generate Token

Authenticate using Basic Authentication with username/password or client credentials.

This endpoint is typically used by a web or mobile application at login when the user first enters their credentials.

Returns an access_token and, optionally, a refresh_token depending on the type of authentication.

Note: The refresh_token is only issued for web or mobile authentication users; it is not returned for machine-to-machine (M2M) authentication.

Header example:

Authorization: Basic base64(username:password)
post/api/auth/token

Response

Token generated successfully

access_tokenstring required

JWT access token used to access secure Clerk Tools APIs.

token_typestring required

Token type; typically 'Bearer'.

expires_ininteger required

Number of seconds until the access token expires.

refresh_tokenstring required

Refresh token used to obtain a new access token. Previous refresh_token expires when a new one is issued. Must be stored securely and never exposed outside the application. Not generated for machine-to-machine (M2M) authentication; only available for web or mobile login.

Example response

{
  "access_token": "eyJhbGciOiJFUzI1NiJ9...",
  "token_type": "Bearer",
  "expires_in": 300,
  "refresh_token": "95CCF8D8-C4D1-4471-8DE5-4B695C065163"
}
All 2 operations