Skip to content

Obtain access token

POST
/oauth2/token
curl --request POST \
--url https://your-cognito-domain.example.com/oauth2/token \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=client_credentials \
--data client_id=example \
--data client_secret=example \
--data 'scope=crm-api/products.read crm-api/products.write'

Exchange client credentials for an access token using the OAuth 2.0 Client Credentials flow. This is a Cognito endpoint (different host), not part of the CRM API. Token lifetime: 1 hour for clients created since #435, 24 hours for older clients — use expires_in.

Media type application/x-www-form-urlencoded
object
grant_type
required
string
Allowed values: client_credentials
client_id
required

Your M2M client ID

string
client_secret
required

Your M2M client secret

string
scope
required

Space-separated scopes.

string
Example
crm-api/products.read crm-api/products.write

Token issued successfully.

Media type application/json
object
access_token
required
string
token_type
required
string
Allowed values: Bearer
expires_in
required

Token lifetime in seconds (3600 for new clients; 86400 for older clients).

integer
Example
{
"token_type": "Bearer"
}

Invalid request (bad credentials or scope).

Media type application/json
object
error
string
Allowed values: invalid_client invalid_scope invalid_grant
error_description
string
Example
{
"error": "invalid_client"
}