Authentication
Request a machine-to-machine access token and use it safely with the approved OmniLab API endpoints.
2 min read
Your backend exchanges its client credentials for a token, then sends that token with every call.
Before you begin
- A
client_id,client_secretandaudiencefor each environment. They aren't self-service: request them from your Customer Success Manager, and confirm which endpoints are enabled for you. - Your API host for each environment, listed in Base URLs and environments.
- A server you control for the token request, never browser code or a mobile app bundle.
Request a token
-
Store the production and staging credentials separately, in a secret manager.
-
Call
POST https://<api-host>/v1/oauth:tokenwith a JSON body:curl -X POST "https://<api-host>/v1/oauth:token" \ -H "Content-Type: application/json" \ -d '{ "client_id": "YOUR_CLIENT_ID", "client_secret": "YOUR_CLIENT_SECRET", "audience": "YOUR_AUDIENCE", "grant_type": "client_credentials" }' -
Read the token from the response:
{ "access_token": "YOUR_ACCESS_TOKEN", "token_type": "Bearer", "expires_in": 3600 }expires_inis the token's lifetime in seconds. Asking again while it's valid can return the same token, with the sameexpires_in. Cache the token, and count its expiry from the first response. -
Send the token in the
Authorizationheader on every API request:Authorization: Bearer YOUR_ACCESS_TOKEN
When a token request or call fails
| Response | Cause | What to do |
|---|---|---|
400 on the token request | client_id or client_secret is missing | Send both, then retry |
500 on the token request | The credentials were refused, or no token could be issued | Check the credentials and audience before you retry |
401 on an API call | The token is missing, expired or malformed, or belongs to another account's host | Request a new token, then retry once |
A token only works on the API host of the account it was issued for.
Security rules that matter
- Never expose the
client_secretin browser JavaScript, a kiosk page or a mobile app bundle. - Keep the token exchange on your own backend, then call the API server to server.
- Store separate credentials per environment.
- Ask your Customer Success Manager to rotate credentials that are compromised or no longer used.
- Log request IDs and timestamps on your side, but never full secrets or full access tokens.