Authentication¶
Authentication Using OAuth2¶
We are able to authenticate with the Everysk API using the OAuth2 Client Credentials grant type. Click here to learn more about this type of authentication
First we need to obtain the acess token,
So using the following headers and body make a POST request to the following endpoint
curl https://api.everysk.com/v2/oauth2/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET" \
-X POST
The response should look something like this:
{
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"token_type": "Bearer",
"expires_in": 3600,
"scope": "GET POST PUT DELETE"
}
The scope field in the response represents the set of permissions granted to the access token. Scopes are application-specific — in the Everysk API, each scope corresponds to an HTTP method and controls what actions the token is allowed to perform.
The scope_str in the response will contain the scopes that were granted to your application.
| Scope | Permission |
|---|---|
GET |
Read access — retrieve entities and their data |
POST |
Create access — create new entities |
PUT |
Modify access — update existing entities |
DELETE |
Delete access — remove entities |
Now include the token in your API calls like this:
where <ACCESS_TOKEN> should be replaced with the value returned in the previous response.
You can manage your OAuth2 credentials (client ID, client secret, and tokens) in the OAuth2 Credentials page.
A few things to keep in mind¶
-
Never expose the
client_secretin frontend code -
Perform token requests on the backend
-
Store credentials securely
-
Refresh token when expired — tokens expire after 1 hour. To get a new one, simply call the same token endpoint again with your
client_idandclient_secret
Authentication Using API Key¶
Deprecated
This authentication method is not recommended for new projects. Please use Authentication Using OAuth2 instead.
Authenticate your account when using the API by including your secret API key in the request. Authentication to the API is performed via HTTP Basic Authentication. API requests without authentication will fail. Create and manage your credentials in the API Keys tab of the API Manager.
A request example with arguments:
The above call returns a JSON structure like this: