Skip to main content
Login
Apus Platform
Docs contents

Authentication

The API uses OAuth 2.0 client credentials. Create an API client in the Account Console to get a client_id and client_secret, then exchange them for a short-lived access token. Each client is granted a set of scopes (for example products:read, inventory:write) — an endpoint returns 403 if its scope is missing.

Send the token as a Bearer token on every request. Tokens expire (expires_in seconds); request a new one when you get a 401. Never expose the client_secret in front-end code — server-to-server only.

# Exchange credentials for an access token
curl -X POST https://api.apusplatform.com/v1/oauth/token \
  -H "Content-Type: application/json" \
  -d '{
    "grant_type": "client_credentials",
    "client_id": "cli_a1b2c3",
    "client_secret": "sk_live_...",
    "scope": "products:read inventory:write orders:read"
  }'

# Response
{ "access_token": "eyJhbGci...", "token_type": "Bearer", "expires_in": 3600 }
noindex