Get access token
Exchanges your client credentials for an access token, which every other endpoint in this API
requires. Send the fields below as application/x-www-form-urlencoded.
See Authentication for how to use the token, how long it lasts, and what it grants you.
Request
This endpoint expects an object.
grant_type
Always client_credentials. This is a machine-to-machine call; there is no user to redirect.
Allowed values:
client_id
The client id UAC issued to your institution.
client_secret
The matching client secret. Treat it as a credential: keep it server-side, never in a browser or mobile app.
Response headers
:status
cache-control
pragma
referrer-policy
strict-transport-security
x-content-type-options
x-frame-options
x-xss-protection
Response
OK
access_token
expires_in
refresh_expires_in
token_type
not-before-policy
scope
