Skip to main content
POST
Create Token

Authentication and permissions

Token requirements: Organization-scoped API key or Team-scoped API key. Send the key’s client ID and secret using HTTP Basic to obtain a token. User-based OAuth tokens are not accepted here.
Permissions joined by + are all required; or separates alternatives. Full-access keys still cannot call endpoints marked unsupported. Team keys must allow every team checked by the request. OAuth access depends on the user’s roles and resource access.
  • Exchange public-key credentials: Use HTTP Basic with client ID and secret and grant_type=client_credentials.

Authorizations

Authorization
string
header
required

Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.

Body

application/x-www-form-urlencoded
grant_type
enum<string>
Available options:
client_credentials

Response

Success

access_token
string

The access token.

token_type
string

The type of token.

expires_in
integer

The number of seconds until the token expires.