Get a bearer token (OAuth 2.0 client credentials)

Exchange your API client_id / client_secret for a bearer token, then send it as Authorization: Bearer <access_token> on subsequent requests.

Lifetime. Tokens are valid for 1 hour (expires_in: 3600). Request a new one before it elapses; on a 401, fetch a fresh token and retry once. Revoking a credential invalidates its tokens within 30 seconds.

Rate limits. At most 30 token requests per minute per IP address; requests made with the token are limited to 600 per minute per credential. Over the limit you receive 429 with a Retry-After header.

Obtaining credentials: generate them in Settings → Integrations → Custom API. Treat the secret like a password — it is shown only once.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
required

API client ID, generated in Settings → API access.

string
required

API client secret. Shown only once when generated — store it securely.

Responses

400

Malformed body: client_id and client_secret must be non-empty strings.

401

Invalid API credentials.

429

Too many token requests from this IP address. Retry after the number of seconds in the Retry-After header.

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json