Hootsuite Rest API Authentication API

Follow the steps below to make an authenticated API request. # 1. Request client credentials ### Step 1: Create your OAuth 2.0 app Follow [these steps](https://developer.hootsuite.com/docs/getting-started-with-the-rest-api) to set up your app and retrieve your client credentials (`client_id` and `client_secret`): ### Step 2: Retrieve the appId of your newly created app 1. Go to your [Hootsuite Developer Apps](https://hootsuite.com/developers/my-apps) dashboard. 2. Select `edit` for your newly created app. 3. You can find the appId in the `appId` parameter of the browser URL. Ex: `https://hootsuite.com/developers/my-apps/app-directory/app/edit?appId=XXXXXX` ### Step 3: Retrieve the organization ID of your Hootsuite organization 1. Sign in into your [Hootsuite account](https://hootsuite.com). 2. Select `My profile > Manage accounts and teams`. 3. Select `Teams` for your organization. 5. You can find the organization ID in the id query parameter in your browser's address bar. ``` https://hootsuite.com/dashboard#/organizations/teams/?id= ``` ### Step 4: Request to link your organization to your app 1. Add a member to your org that is not a paying member 2. Make sure they have at least admin permission level 3. Send an email to the Development Support Team to link your organization to your app: - To: `dev.support@hootsuite.com` - Include: - the `appId` you retrieved in *Step 2* - the `organization ID` you retrieved in *Step 3* - the `member ID` of the non-paying admin member 4. Wait for the Development Support Team to link your app to your organization. # 2. Generate an access token When the developer app is correctly set up, you can use your `client_id` and `client_secret` to retrieve an `access_token` to make authorized API requests. When the `access_token` expires, use the [/oauth2/token](#operation/oauthToken) to generate a new token. This endpoint requires that you pass in your client credentials (`client_id` and `client_secret`) using the HTTP Basic authentication scheme as described in the [OAuth 2.0 specification](https://datatracker.ietf.org/doc/html/rfc6749#section-2.3.1). Including your client credentials in the request-body is not supported. When the `access_token` expires, the API returns a 401 unauthorized. The client can automate this by generating a new access token and replaying the failed request with the fresh access token, as described in the following section. # 3. Include the access token as a bearer token Authorization header Add the bearer token in the Authorization header ```text Authorization: Bearer ``` Example request with token ```shell $ curl -X GET https://platform.hootsuite.com/inbox/v1/reporting/metrics/agent-availability \ -H 'Authorization: Bearer oZy8FDUHEiZ0mh0j4rUwOT9t5yHouTzBDsn-x_GROB0.rz-pMQzh-1F6VIGwnJZMBwH3SRwDfEHE4CRi-AClpcg' ```

Operations 1

POST /oauth2/token OAuth2 Token #

Documentation

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/hootsuite-rest-api-authentication-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

hootsuite-rest-api-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Inbox 2.0 API Reference Rest API Authentication API
  description: Inbox 2.0 API Reference
  version: v1
  x-logo:
    url: static/hootsuite-logo.png
  contact:
    email: dev.support@hootsuite.com
  license:
    name: Hootsuite Developer Terms and API License Agreement
    url: https://hootsuite.com/legal/dev-api-terms
servers:
- url: https://platform.hootsuite.com
  description: Inbox 2.0 production server
security:
- bearer-token: []
tags:
- name: rest-api-authentication
  x-displayName: REST API authentication
  description: Follow the steps below to make an authenticated API request.
paths:
  /oauth2/token:
    post:
      tags:
      - rest-api-authentication
      summary: OAuth2 Token
      operationId: oauthToken
      description: 'OAuth2 Token endpoint.


        This endpoint requires that you pass in your client credentials using the HTTP Basic authentication scheme as outlined in the spec.

        Including your client credentials in the request-body is not supported.'
      parameters:
      - name: Authorization
        in: header
        description: A base64-encoded client_id:client_secret string used for authentication.
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              required:
              - grant_type
              - organization_id
              properties:
                grant_type:
                  type: string
                  description: The OAuth2 grant_type used. Must be set to *organization_app*.
                  enum:
                  - organization_app
                organization_id:
                  type: string
                  description: The id of your organization. The organization must be linked to your app.
              example:
                grant_type: organization_app
                organization_id: 900002
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json;charset=utf-8:
              schema:
                $ref: '#/components/schemas/OAuth2BearerToken'
        '401':
          description: Unauthorized
          content:
            application/json;charset=utf-8:
              schema:
                $ref: '#/components/schemas/OAuthError'
      security:
      - basic-auth: []
components:
  schemas:
    OAuth2BearerToken:
      type: object
      properties:
        access_token:
          type: string
          description: 'The token used to authorize requests. This should be added to requests as an authorization header: `Authorization: Bearer oZy8FDUHEiZ0mh0j4rUwOT9t5yHouTzBDsn-x_GROB0.rz-pMQzh-1F6VIGwnJZMBwH3SRwDfEHE4CRi-AClpcg`

            '
          example: oZy8FDUHEiZ0mh0j4rUwOT9t5yHouTzBDsn-x_GROB0.rz-pMQzh-1F6VIGwnJZMBwH3SRwDfEHE4CRi-AClpcg
        token_Type:
          type: string
          description: The token type to be used in the authorization header. This will always be *bearer* for client credentials grant.
          example: bearer
        expires_in:
          type: number
          description: The number of seconds until the token expires (1 hour)
          example: 3599
    OAuthError:
      type: object
      properties:
        error:
          type: string
          description: An error code indicating the type of error that occurred. Should be used in conjunction with HTTP status.
          enum:
          - request_unauthorized
          - request_forbidden
          - invalid_request
          - unauthorized_client
          - access_denied
          - unsupported_response_type
          - invalid_scope
          - server_error
          - temporarily_unavailable
          - unsupported_grant_type
          - invalid_grant
          - invalid_client
          - unknown_error
          - not_found
          - invalid_state
          - misconfiguration
          - insufficient_entropy
          - invalid_token
          - token_signature_mismatch
          - token_expired
          - scope_not_granted
          - token_claim
          - token_inactive
        error_description:
          type: string
          description: A description of error.
          example: An error message
        error_hint:
          type: string
          description: A helpful hint about the error.
          example: Make sure that the various parameters are correct, be aware of case sensitivity and trim your parameters.
        status_code:
          type: number
          description: The status code
          example: 401
  securitySchemes:
    bearer-token:
      type: http
      scheme: bearer
    basic-auth:
      type: http
      scheme: basic
    Oauth2ClientCredentials:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: TO_BE_CONFIGURED_IN_INBOX_2_0
          scopes:
            some_scope: TO_BE_CONFIGURED_IN_INBOX_2_0
    SharedSecret:
      type: apiKey
      in: header
      name: X-Hootsuite-Signature
x-tagGroups:
- name: General
  tags:
  - rest-api-authentication
- name: CRM API
  tags:
  - crm_introduction
  - crm_webhooks
  - crm_rest_api
- name: Virtual Agent API
  tags:
  - vai_introduction
  - vai_webhooks
  - vai_rest_api
- name: Real-time metrics API
  tags:
  - real_time_metrics_introduction
  - real_time_metrics_rest_api
- name: User Presence API
  tags:
  - user_presence_introduction
  - user_presence_rest_api
- name: Queue API
  tags:
  - queue_introduction
  - queue_rest_api
- name: Proactive messaging API
  tags:
  - proactive_messaging_introduction
  - proactive_messaging_rest_api
- name: Messenger SDK
  tags:
  - messenger_introduction
  - messenger_web_sdk