Bỏ qua để tới nội dung chính
Đăng nhập
Apus Platform
Mục lục tài liệu

Authentication

The API uses OAuth 2.0 client credentials. Create an API client in the Account Console to get a client_id and client_secret, then exchange them for a short-lived access token. Each client is granted a set of scopes (for example products:read, inventory:write) — an endpoint returns 403 if its scope is missing.

Send the token as a Bearer token on every request. Tokens expire (expires_in seconds); request a new one when you get a 401. Never expose the client_secret in front-end code — server-to-server only.

# Exchange credentials for an access token
curl -X POST https://api.apusplatform.com/v1/oauth/token \
  -H "Content-Type: application/json" \
  -d '{
    "grant_type": "client_credentials",
    "client_id": "cli_a1b2c3",
    "client_secret": "sk_live_...",
    "scope": "products:read inventory:write orders:read"
  }'

# Response
{ "access_token": "eyJhbGci...", "token_type": "Bearer", "expires_in": 3600 }
noindex