Elastic Path Generate an Access Token API
The Generate an Access Token API from Elastic Path — 1 operation(s) for generate an access token.
The Generate an Access Token API from Elastic Path — 1 operation(s) for generate an access token.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/elastic-path-generate-an-access-token-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Authentication Generate an Access Token API
description: All API endpoints require authentication.
contact:
name: Elastic Path
url: https://www.elasticpath.com
email: support@elasticpath.com
version: 26.0218.7213153
x-version-timestamp: 2026-02-18 18:20:34+00:00
license:
name: MIT
url: https://raw.githubusercontent.com/elasticpath/elasticpath-dev/main/LICENSE
servers:
- url: https://useast.api.elasticpath.com
description: US East
- url: https://euwest.api.elasticpath.com
description: EU West
security: []
tags:
- name: Generate an Access Token
paths:
/oauth/access_token:
post:
tags:
- Generate an Access Token
summary: Create an Access Token
operationId: CreateAnAccessToken
description: '### Client Credentials
A `client_credentials` token is used when the credentials are not publicly exposed, usually a server-side language such as PHP or Node.js. This type of authentication enables `CRUD` access to all resources.
`client_id` and `client_secret` are created and managed via Application Keys.
To see the access granted by a `client_credentials` token, refer to Permissions.
### Implicit
An `implicit` token is typically used for situations where you are requesting data on the client side and you are exposing your public key. When authenticated implicitly, you can only fetch (`GET`) data with live status (products, categories, brands, etc).
The `implicit` token is most appropriate for use inside client-side applications, such as JavaScript.
:::caution
An `implicit` token can be thought of as a **Read only** token.
:::'
requestBody:
$ref: '#/components/requestBodies/CreateAccessToken'
responses:
'200':
$ref: '#/components/responses/AccessToken'
'400':
$ref: '#/components/responses/BadRequestError'
'401':
$ref: '#/components/responses/UnauthorizedError'
'500':
$ref: '#/components/responses/InternalServerError'
components:
schemas:
Errors:
required:
- errors
properties:
errors:
type: array
items:
type: object
required:
- status
- title
properties:
status:
type: string
description: The HTTP response code of the error.
format: string
examples:
- '400'
title:
type: string
description: A brief summary of the error.
examples:
- Bad Request
detail:
type: string
description: Optional additional detail about the error.
examples:
- The field 'name' is required
responses:
UnauthorizedError:
description: Unauthorized
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
examples:
unauthorized-error:
summary: Unauthorized
value: "{\n \"errors\": [\n {\n \"title\": \"Unauthorized\",\n \"status\": \"401\",\n \"detail\": \"Unauthorized\"\n }\n ]\n}\n"
AccessToken:
description: Access Token
content:
application/json:
schema:
type: object
properties:
access_token:
type: string
description: The access token you use to authenticate requests to the API.
token_type:
type: string
description: Right now this is only `Bearer`.
identifier:
type: string
description: The type of token requested. This can be a `client_credentials` or `implicit`.
expires_in:
type: integer
description: The duration in seconds after which the token expires.
expires:
type: integer
description: The epoch time that this token expires at.
examples:
Client Credentials:
summary: Access token from Client Credentials
value:
access_token: xa3521ca621113e44eeed9232fa3e54571cb08bc
token_type: Bearer
expires_in: 3600
expires: 1524486008
identifier: client_credentials
Implicit:
summary: Access token from Implicit
value:
access_token: xa3521ca621113e44eeed9232fa3e54571cb08bc
token_type: Bearer
expires_in: 3600
expires: 1524486008
identifier: implicit
BadRequestError:
description: Bad Request
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
examples:
bad-request-error:
summary: Bad Request
value: "{\n \"errors\": [\n {\n \"title\": \"Bad Request\",\n \"status\": \"400\",\n \"detail\": \"The field 'name' is required\"\n }\n ]\n}\n"
InternalServerError:
description: Internal server error. There was a system failure in the platform.
content:
application/json:
schema:
$ref: '#/components/schemas/Errors'
examples:
internal-server-error:
summary: Internal server error
value: "{\n \"errors\": [\n {\n \"title\": \"Internal Server Error\",\n \"status\": \"500\",\n \"detail\": \"there was a problem processing your request\"\n }\n ]\n}\n"
requestBodies:
CreateAccessToken:
content:
application/x-www-form-urlencoded:
schema:
type: object
required:
- grant_type
- client_id
properties:
grant_type:
type: string
description: The grant type.
enum:
- client_credentials
- implicit
client_id:
type: string
description: Your `client_id`
client_secret:
type: string
description: Your `client_secret`. Only required for client credentials.
examples:
Create Example:
summary: Create an Access Token using Client Credentials
value:
grant_type: client_credentials
client_id: jJBrLb0q1Q7bZ5GiGttD5T1471b0IeXAVgNyOlw19q
client_secret: mzr6gnvdQODSgT3mSxxWIv3y8pAp8cUzDELXa3g4fB