Skip to navigation

Get access token

View as Markdown

Exchanges your client credentials for an access token, which every other endpoint in this API requires. Send the fields below as application/x-www-form-urlencoded.

See Authentication for how to use the token, how long it lasts, and what it grants you.

Request

This endpoint expects an object.
grant_typeenumRequiredDefaults to client_credentials

Always client_credentials. This is a machine-to-machine call; there is no user to redirect.

Allowed values:
client_idstringRequired
The client id UAC issued to your institution.
client_secretstringRequiredformat: "password"

The matching client secret. Treat it as a credential: keep it server-side, never in a browser or mobile app.

Response headers

:statusstringOptional
cache-controlstringOptional
pragmastringOptional
referrer-policystringOptional
strict-transport-securitystringOptional
x-content-type-optionsstringOptional
x-frame-optionsstringOptional
x-xss-protectionstringOptional

Response

OK
access_tokenstring
expires_ininteger
refresh_expires_ininteger
token_typestring
not-before-policyinteger
scopestring