Skip to main content
Every authenticated call carries two credentials: your API key, and a bearer token you fetch first. This page gets you authenticated and nothing more — the two calls, the shape they return, and the two ways they fail. The endpoint itself, with every field and a live “Try it”, is Get access token.

Get a token

Only the API key is needed for this call. The client id and password go in the body.
The token comes back nested under data:
Read the lifetime from data.expires_in rather than assuming it. It is set per account, so a number you hard-code from one environment can be wrong in another.

When it fails

Both come back with a message that talks about routing whichever the cause, so read the status code rather than the text. Check the headers first.

Your first call

Create something and read it back.