Get Access Token
POST/oauth2/token
Use this endpoint to retrieve an access token for the REST API. Send the Client ID and Client Secret of your REST API key as form fields, together with grant_type. The body must be form encoded: a JSON body is rejected with invalid_request.
The token is valid for 30 minutes. There is no refresh token. When it expires, request a new one with the same credentials. See Authentication and security for renewal and error handling.
The endpoint also accepts the Client ID and Client Secret as HTTP Basic authentication, with only grant_type in the body.
Request
Responses
- 200
- 400
- 401
The access token and its lifetime.
The request is malformed. unsupported_grant_type means grant_type has another value than client_credentials. invalid_request means grant_type is missing, which is also what a JSON body produces.
The credentials are wrong. An unknown Client ID returns invalid_client and a known Client ID with the wrong secret returns unauthorized_client. Both carry the same description.