Skip to content

Request an access token

POST
/auth/token/
curl --request POST \
--url https://app.commitly.com/api/auth/token/ \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=client_credentials \
--data client_id=YOUR_CLIENT_ID \
--data client_secret=YOUR_CLIENT_SECRET

Exchanges the Client ID and Client Secret for an access token (OAuth 2.0 client credentials grant). Send the credentials in the request body as application/x-www-form-urlencoded, multipart/form-data or application/json. HTTP Basic authentication of the client is not supported.

The access token is valid for 5 minutes. When it has expired, request a new token with the client credentials.

object
grant_type
required
string
Allowed value: client_credentials
client_id
required

Client ID from Add-ons > COMMITLY Public API.

string
client_secret
required

Client Secret from Add-ons > COMMITLY Public API.

string
Example
grant_type=client_credentials&client_id=YOUR_CLIENT_ID&client_secret=YOUR_CLIENT_SECRET

Access token issued.

Media typeapplication/json
object
access_token
required

Send as Authorization: Bearer <access_token>.

string
token_type
required

Always bearer (lowercase).

string
Allowed value: bearer
refresh_token

Refresh token.

string
expires_in
required

Lifetime of the access token in seconds (300, i.e. 5 minutes).

integer
refresh_expires_in

Lifetime of the refresh token in seconds (1209600, i.e. 14 days).

integer
scope

Space-separated scopes of the token, or all.

string
Example
{
"access_token": "YOUR_ACCESS_TOKEN",
"token_type": "bearer",
"refresh_token": "YOUR_REFRESH_TOKEN",
"expires_in": 300,
"refresh_expires_in": 1209600,
"scope": "all"
}

Invalid or missing client credentials. The message is localized (see Accept-Language).

Media typeapplication/json
object
non_field_errors

Error messages. Localized (see Accept-Language).

Array<string>
Example
{
"non_field_errors": [
"Invalid client credentials."
]
}