Get an access token
OAuth 2.0 client credentials (RFC 6749 section 4.4). Send the Client ID and client secret with HTTP Basic
(Authorization: Basic base64(client_id:client_secret), each part form-url-encoded first) or as
client_id and client_secret in the form, not both. The body is always a form
(application/x-www-form-urlencoded).
audience names the account: https://api.envoi.no/v1/accounts/P11112001 for production or
https://api.envoi.no/v1/accounts/T11112001 for its Testmiljø. The client needs an active grant for that
environment.
The token lives 15 minutes (expires_in). There is no refresh token: ask again with the same credentials.
Errors use the OAuth shape { "error": "..." }.
curl https://api.envoi.no/v1/oauth/token \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-d grant_type=client_credentials \
-d audience=https://api.envoi.no/v1/accounts/P11112001
Authorizations
For the token endpoint only: the Client ID and client secret as HTTP Basic (each part form-url-encoded first, RFC 6749 section 2.3.1).
Body
The form the token endpoint reads (application/x-www-form-urlencoded).
Always client_credentials.
The account the token is for: https://api.envoi.no/v1/accounts/{accountId}. The Account ID's prefix picks the environment: P is production, T is the Testmiljø.
The Client ID, when the credentials are not sent with HTTP Basic.
The client secret, when the credentials are not sent with HTTP Basic. Refused next to an HTTP Basic header.
Response
The access token.
An access token.
The bearer token. Send it as Authorization: Bearer {access_token}.
Always Bearer.
Seconds until the token expires (900, 15 minutes). There is no refresh token: ask for a new one with the same credentials.
The grant's scopes, space separated.