Access and Refresh Token API

Getting an Access Token

POST - /rest/oauth/token


The following headers should be included in your request:

      Content-Type: application/x-www-form-urlencoded;charset=utf-8     
      TenantRegion: [ APAC | EU | US ]


grant_type=refresh_token&client_id=xxxxxxxx&client_secret=yyyyyyyy&refresh_token=zzzzzzzz&redirect_uri=https://m y.app.com/oauth2callback 


If successful, you will receive a JSON response with the required tokens, where ‘expires_in’ is measured in seconds.


"access_token": "xxxxxxxx", "refresh_token": "yyyyyyyy", "token_type" : "BEARER", "expires_in": 21600 }

If there are any problems with the request, you'll receive a 400 response with an error message.


"error": "error_code",
 "error_description" : "A human readable error message" }

Once the access token is obtained, it needs to be passed in the Header for all API Calls.

      Authorization : Bearer <access_token>