Obtain access token
POST
/oauth2/token
const url = 'https://your-cognito-domain.example.com/oauth2/token';const options = { method: 'POST', headers: {'Content-Type': 'application/x-www-form-urlencoded'}, body: new URLSearchParams({ grant_type: 'client_credentials', client_id: 'example', client_secret: 'example', scope: 'crm-api/products.read crm-api/products.write' })};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://your-cognito-domain.example.com/oauth2/token \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data grant_type=client_credentials \ --data client_id=example \ --data client_secret=example \ --data 'scope=crm-api/products.read crm-api/products.write'Exchange client credentials for an access token using the OAuth 2.0
Client Credentials flow. This is a Cognito endpoint (different host),
not part of the CRM API. Token lifetime: 1 hour for clients created
since #435, 24 hours for older clients — use expires_in.
Request Body required
Section titled “Request Body required ” Media type application/x-www-form-urlencoded
object
grant_type
required
string
client_id
required
Your M2M client ID
string
client_secret
required
Your M2M client secret
string
scope
required
Space-separated scopes.
string
Example
crm-api/products.read crm-api/products.writeResponses
Section titled “ Responses ”Token issued successfully.
Media type application/json
object
access_token
required
string
token_type
required
string
expires_in
required
Token lifetime in seconds (3600 for new clients; 86400 for older clients).
integer
Example
{ "token_type": "Bearer"}Invalid request (bad credentials or scope).
Media type application/json
object
error
string
error_description
string
Example
{ "error": "invalid_client"}