Skip to main content
POST
Get an access token

Authorizations

Authorization
string
header
required

For the token endpoint only: the Client ID and client secret as HTTP Basic (each part form-url-encoded first, RFC 6749 section 2.3.1).

Body

application/x-www-form-urlencoded

The form the token endpoint reads (application/x-www-form-urlencoded).

grant_type
string
required

Always client_credentials.

audience
string
required

The account the token is for: https://api.envoi.no/v1/accounts/{accountId}. The Account ID's prefix picks the environment: P is production, T is the Testmiljø.

client_id
string | null

The Client ID, when the credentials are not sent with HTTP Basic.

client_secret
string | null

The client secret, when the credentials are not sent with HTTP Basic. Refused next to an HTTP Basic header.

Response

The access token.

An access token.

access_token
string
required

The bearer token. Send it as Authorization: Bearer {access_token}.

token_type
string
required

Always Bearer.

expires_in
integer<int32>
required

Seconds until the token expires (900, 15 minutes). There is no refresh token: ask for a new one with the same credentials.

scope
string
required

The grant's scopes, space separated.