Skip to content

Authentication

Authentication Using OAuth2

We are able to authenticate with the Everysk API using the OAuth2 Client Credentials grant type. Click here to learn more about this type of authentication

First we need to obtain the acess token,

So using the following headers and body make a POST request to the following endpoint

curl https://api.everysk.com/v2/oauth2/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET" \
  -X POST

The response should look something like this:

{
  "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "scope": "GET POST PUT DELETE"
}

The scope field in the response represents the set of permissions granted to the access token. Scopes are application-specific — in the Everysk API, each scope corresponds to an HTTP method and controls what actions the token is allowed to perform.

The scope_str in the response will contain the scopes that were granted to your application.

Scope Permission
GET Read access — retrieve entities and their data
POST Create access — create new entities
PUT Modify access — update existing entities
DELETE Delete access — remove entities

Now include the token in your API calls like this:

curl https://api.everysk.com/v2/... \
  -H "Authorization: Bearer <ACCESS_TOKEN>"

where <ACCESS_TOKEN> should be replaced with the value returned in the previous response.

You can manage your OAuth2 credentials (client ID, client secret, and tokens) in the OAuth2 Credentials page.

A few things to keep in mind

  • Never expose the client_secret in frontend code

  • Perform token requests on the backend

  • Store credentials securely

  • Refresh token when expired — tokens expire after 1 hour. To get a new one, simply call the same token endpoint again with your client_id and client_secret


Authentication Using API Key


Deprecated

This authentication method is not recommended for new projects. Please use Authentication Using OAuth2 instead.

Authenticate your account when using the API by including your secret API key in the request. Authentication to the API is performed via HTTP Basic Authentication. API requests without authentication will fail. Create and manage your credentials in the API Keys tab of the API Manager.


A request example with arguments:

curl https://api.everysk.com/v2/health_check \
  -H "Authorization: Bearer YOUR_ACCOUNT_SID:YOUR_AUTH_TOKEN" \
  -G


The above call returns a JSON structure like this:

{
  "api_status": "OK",
  "version": "v2",
  "name": "Everysk API"
}