Generate OAuth access token
curl --request POST \
--url https://api.example.com/oauth/token \
--header 'Content-Type: application/json' \
--data '
{
"clientId": "app_1234567890abcdef",
"clientSecret": "cs_1234567890abcdef",
"scopes": [
"read:organization"
],
"userId": "550e8400-e29b-41d4-a716-446655440000"
}
'import requests
url = "https://api.example.com/oauth/token"
payload = {
"clientId": "app_1234567890abcdef",
"clientSecret": "cs_1234567890abcdef",
"scopes": ["read:organization"],
"userId": "550e8400-e29b-41d4-a716-446655440000"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
clientId: 'app_1234567890abcdef',
clientSecret: 'cs_1234567890abcdef',
scopes: ['read:organization'],
userId: '550e8400-e29b-41d4-a716-446655440000'
})
};
fetch('https://api.example.com/oauth/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/oauth/token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientId' => 'app_1234567890abcdef',
'clientSecret' => 'cs_1234567890abcdef',
'scopes' => [
'read:organization'
],
'userId' => '550e8400-e29b-41d4-a716-446655440000'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/oauth/token"
payload := strings.NewReader("{\n \"clientId\": \"app_1234567890abcdef\",\n \"clientSecret\": \"cs_1234567890abcdef\",\n \"scopes\": [\n \"read:organization\"\n ],\n \"userId\": \"550e8400-e29b-41d4-a716-446655440000\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/oauth/token")
.header("Content-Type", "application/json")
.body("{\n \"clientId\": \"app_1234567890abcdef\",\n \"clientSecret\": \"cs_1234567890abcdef\",\n \"scopes\": [\n \"read:organization\"\n ],\n \"userId\": \"550e8400-e29b-41d4-a716-446655440000\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/oauth/token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"clientId\": \"app_1234567890abcdef\",\n \"clientSecret\": \"cs_1234567890abcdef\",\n \"scopes\": [\n \"read:organization\"\n ],\n \"userId\": \"550e8400-e29b-41d4-a716-446655440000\"\n}"
response = http.request(request)
puts response.read_bodyOAuth
Generate OAuth Access Token
🔓 PUBLIC ENDPOINT: Generates an OAuth2 access token using client credentials flow. Requires valid client_id and client_secret. Token scopes are validated against application configuration. Rate limit: 10 requests per minute.
POST
/
oauth
/
token
Generate OAuth access token
curl --request POST \
--url https://api.example.com/oauth/token \
--header 'Content-Type: application/json' \
--data '
{
"clientId": "app_1234567890abcdef",
"clientSecret": "cs_1234567890abcdef",
"scopes": [
"read:organization"
],
"userId": "550e8400-e29b-41d4-a716-446655440000"
}
'import requests
url = "https://api.example.com/oauth/token"
payload = {
"clientId": "app_1234567890abcdef",
"clientSecret": "cs_1234567890abcdef",
"scopes": ["read:organization"],
"userId": "550e8400-e29b-41d4-a716-446655440000"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
clientId: 'app_1234567890abcdef',
clientSecret: 'cs_1234567890abcdef',
scopes: ['read:organization'],
userId: '550e8400-e29b-41d4-a716-446655440000'
})
};
fetch('https://api.example.com/oauth/token', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/oauth/token",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'clientId' => 'app_1234567890abcdef',
'clientSecret' => 'cs_1234567890abcdef',
'scopes' => [
'read:organization'
],
'userId' => '550e8400-e29b-41d4-a716-446655440000'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/oauth/token"
payload := strings.NewReader("{\n \"clientId\": \"app_1234567890abcdef\",\n \"clientSecret\": \"cs_1234567890abcdef\",\n \"scopes\": [\n \"read:organization\"\n ],\n \"userId\": \"550e8400-e29b-41d4-a716-446655440000\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/oauth/token")
.header("Content-Type", "application/json")
.body("{\n \"clientId\": \"app_1234567890abcdef\",\n \"clientSecret\": \"cs_1234567890abcdef\",\n \"scopes\": [\n \"read:organization\"\n ],\n \"userId\": \"550e8400-e29b-41d4-a716-446655440000\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/oauth/token")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"clientId\": \"app_1234567890abcdef\",\n \"clientSecret\": \"cs_1234567890abcdef\",\n \"scopes\": [\n \"read:organization\"\n ],\n \"userId\": \"550e8400-e29b-41d4-a716-446655440000\"\n}"
response = http.request(request)
puts response.read_bodyGenerates an OAuth2 access token using client credentials flow.
This is a PUBLIC ENDPOINT (no authentication required). Rate-limited to
10 requests per minute.
Request Body
| Field | Type | Required | Description |
|---|---|---|---|
clientId | string | Yes | Client ID of the OAuth application |
clientSecret | string | Yes | Client secret of the OAuth application |
scopes | array | Yes | OAuth scopes requested |
userId | string | No | User ID for user-specific tokens |
Example Request
curl -X POST https://api.timbrix.mx/oauth/token \
-H "Content-Type: application/json" \
-d '{
"clientId": "app_1234567890abcdef",
"clientSecret": "cs_1234567890abcdef",
"scopes": ["read:organization"]
}'
import { Timbrix } from "@timbrix/sdk"
const client = new Timbrix()
const token = await client.oauth.generateToken({
clientId: "app_1234567890abcdef",
clientSecret: "cs_1234567890abcdef",
scopes: ["read:organization"],
})
console.log(token.access_token)
Example Response
{
"access_token": "eyJhbGciOiJIUzI1NiIs...",
"token_type": "Bearer",
"expires_in": 3600,
"scope": "read:organization"
}
Token Scopes
Token scopes are validated against the OAuth application configuration. Only scopes configured for the application can be requested.Using the Token
Include the access token in API requests:curl -X GET https://api.timbrix.mx/users/me \
-H "Authorization: Bearer eyJhbGciOiJIUzI1NiIs..."
Token Expiry
Access tokens expire after 1 hour (3600 seconds). Use the refresh token endpoint to get a new token.Common Errors
400 Bad Request
Invalid request. Check required fields: client_id, client_secret, scopes.401 Unauthorized
Invalid client credentials. Check client_id and client_secret.429 Too Many Requests
Rate limit exceeded. Maximum 10 requests per minute for token generation.Body
application/json
Client ID of the OAuth application
Example:
"app_1234567890abcdef"
Client secret of the OAuth application
Example:
"cs_1234567890abcdef"
OAuth scopes requested
Example:
["read:organization"]
User ID for user-specific tokens
Example:
"550e8400-e29b-41d4-a716-446655440000"
Response
Access token generated successfully. Returns token, type (Bearer), expiration time, and granted scopes.