Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
openapi: 3.2.0
info:
title: Authentication OAUTH API
version: 1.0.0
servers:
- url: https://auth.ocrolus.com
tags:
- name: OAuth
paths:
/oauth/token:
post:
summary: Grant authentication token
operationId: grant-authentication-token
description: 'Retrieve a JWT-compliant access token for use with all other endpoints.
---
> 📘
> All tokens currently expire after 24 hours (86,400 seconds), but we suggest refreshing tokens every 12 hours (43,200 seconds).
Here''s an example of using the returned token in an API call:
```cURL
curl \
--url "https://api.ocrolus.com/v1/books" \
--oauth2-bearer "eyJhbGciOiJ...2hUye_4CpIvQ"
```
See our guide on using API credentials for more details.
This endpoint is OAuth 2.0-compliant. A successful response from this endpoint adheres to the structure given in RFC 6749, section 5.1, while a failed response adheres to the structure given in section 5.2. As a consequence, you can use this endpoint in OAuth 2.0 clients and libraries without needing to explicitly call it in your own code.'
requestBody:
content:
application/json:
schema:
type: object
required:
- grant_type
- client_id
- client_secret
properties:
grant_type:
type: string
description: The OAuth 2.0 grant type for the returned token. Must have a value of `client_credentials`, as we don't offer other grant types at this time.
enum:
- client_credentials
default: client_credentials
audience:
type: string
description: The domain in which the token will be used. We currently only support the value of `https://api.ocrolus.com/` (including the trailing /).
enum:
- https://api.ocrolus.com/
client_id:
type: string
description: The client ID that was generated from the Ocrolus Dashboard.
client_secret:
type: string
description: The client secret associated with the client ID that was generated from the Ocrolus Dashboard.
example:
grant_type: client_credentials
audience: https://api.ocrolus.com/
client_id: CLIENT_ID_EXAMPLE
client_secret: CLIENT_SECRET_EXAMPLE
x-readme:
samples-languages:
- curl
- python
explorer-enabled: false
responses:
'200':
description: Success
content:
application/json:
examples:
Success:
value:
access_token: eyJz93a...k4laUWw
token_type: Bearer
expires_in: 86400
schema:
title: Success
type: object
properties:
access_token:
type: string
description: A JWT-compliant access token for use with all other endpoints.
example: eyJz93a...k4laUWw
token_type:
type: string
description: The type of access token received.
example: Bearer
expires_in:
type: integer
description: The amount of time before the provided access token becomes invalid.
'400':
description: Unauthorized
content:
application/json:
examples:
Unauthorized:
value:
error: access_denied
error_description: Unauthorized
schema:
title: Unauthorized
type: object
properties:
error:
type: string
description: The received error from the request.
example: access_denied
error_description:
type: string
description: An explanation of the stated error.
example: Unauthorized
tags:
- OAuth