Exchange your API client_id / client_secret for a bearer token, then send it as Authorization: Bearer <access_token> on subsequent requests.
Lifetime. Tokens are valid for 1 hour (expires_in: 3600). Request a new one before it elapses; on a 401, fetch a fresh token and retry once. Revoking a credential invalidates its tokens within 30 seconds.
Rate limits. At most 30 token requests per minute per IP address; requests made with the token are limited to 600 per minute per credential. Over the limit you receive 429 with a Retry-After header.
Obtaining credentials: generate them in Settings → Integrations → Custom API. Treat the secret like a password — it is shown only once.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
400Malformed body: client_id and client_secret must be non-empty strings.
401Invalid API credentials.
429Too many token requests from this IP address. Retry after the number of seconds in the Retry-After header.
