Request an Access Token
Make a POST request tohttps://auth.smokeball.com/oauth2/token with the following parameters and headers:
string
required
Basic Authentication header containing the
client_id and client_secret (base64-encoded).Format: Basic base64(client_id:client_secret).Example: Basic Y2xpZW50X2lkOmNsaWVudF9zZWNyZXQ=string
required
Must be set to
application/x-www-form-urlencoded.
Ensures the request body is properly encoded.string
required
Must be set to
client_credentials for this OAuth 2.0 flow.Indicates the request is for client credentials grant.string
required
The client identifier that has been issued.Used to authenticate the client making the request.
The Authorization header must be the string βBasicβ followed by your client_id and client_secret with a colon : in between, Base64 Encoded. For example, client_id:client_secret is Y2xpZW50X2lkOmNsaWVudF9zZWNyZXQ=Sample Response
string
The token to use in the
Authorization header when making API requests.number
The lifetime of the access token in seconds.After expiration, a new token must be obtained.
string
The type of token returned. Always
Bearer.Caching Access Tokens
We recommend caching your access token and reusing it until it expires, rather than requesting a new token for every API request. Requesting a token on every request adds latency to each call and places unnecessary load on the token endpoint. When you receive a token, store it along with its expiry time (calculated fromexpires_in, which is the token lifetime in seconds). Reuse the cached token for all API requests until it is close to expiry, then request a new one. A common approach is to refresh the token slightly before it expires (for example, 60 seconds early) to avoid using an expired token on an in-flight request.
See Making Requests - Server-to-Server requests for details on using Client Credentials.