Skip to main content

Authentication

Every route except this one takes a bearer token. A key never travels as a bearer token itself.

Exchange a key for an access token​

POST /v1/token

Send your ClientID and secret as HTTP Basic credentials. The response carries a bearer token that every other route accepts for 15 minutes. Exchange again when it expires; the SDKs do this for you.

Responses​

  • 200 OK: accessToken, tokenType, expiresIn
  • 401 Unauthorized: code, message

Example​

curl -X POST https://server.api.throughline.dk/v1/token \
-u "$THROUGHLINE_CLIENT_ID:$THROUGHLINE_CLIENT_SECRET"