Zuora O Auth API

Zuora recommends that you use OAuth v2.0 to authenticate to the Zuora REST API. You must first create an OAuth client in the Zuora UI before using the [Create an OAuth token](/api-references/api/operation/createToken) operation to create an OAuth token. See [Authentication](/rest-api/general-concepts/authentication/) for more information.

Operations 1

POST /oauth/token Create an OAuth token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/zuora-oauth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

zuora-oauth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: '2023-12-15'
  title: Reference O Auth API
  description: '# Introduction


    Welcome to the REST API reference for the Zuora Billing, Payments, and Central Platform!'
  contact:
    email: docs@zuora.com
servers:
- url: https://rest.zuora.com/
tags:
- name: OAuth
  description: 'Zuora recommends that you use OAuth v2.0 to authenticate to the Zuora REST API.


    You must first create an OAuth client in the Zuora UI before using the Create an OAuth token operation to create an OAuth token. See Authentication for more information.'
paths:
  /oauth/token:
    post:
      tags:
      - OAuth
      summary: Create an OAuth token
      operationId: createToken
      description: 'Creates a bearer token that enables an OAuth client to authenticate with the Zuora REST API. The OAuth client must have been created using the Zuora UI. See Authentication for more information.


        **Note:** When using this operation, do not set any authentication headers such as `Authorization`, `apiAccessKeyId`, or `apiSecretAccessKey`.


        You should not use this operation to generate a large number of bearer tokens in a short period of time; each token should be used until it expires. If you receive a 429 Too Many Requests response when using this operation, reduce the frequency of requests. This endpoint is rate limited by IP address.


        For the rate limit information of authentication, see Rate and concurrent request limits.'
      parameters:
      - $ref: '#/components/parameters/GLOBAL_HEADER_Zuora_Track_Id'
      responses:
        200:
          headers:
            Zuora-Request-Id:
              description: 'The Zuora internal identifier of the API call. You cannot control the value of this header.

                '
              schema:
                type: string
                maxLength: 36
                minLength: 36
            Zuora-Track-Id:
              description: 'A custom identifier for tracing the API call. If you specified a tracing identifier in the request headers, Zuora returns the same tracing identifier. Otherwise, Zuora does not set this header.

                '
              schema:
                type: string
                maxLength: 64
            X-RateLimit-Limit-minute:
              description: 'The rate limit of this operation, in requests per minute. See [rate limits](https://knowledgecenter.zuora.com/BB_Introducing_Z_Business/Policies/Concurrent_Request_Limits#Rate_limits) for more information.

                '
              schema:
                type: integer
            X-RateLimit-Remaining-minute:
              description: 'The number of requests that you may make in the next minute. See [rate limits](https://knowledgecenter.zuora.com/BB_Introducing_Z_Business/Policies/Concurrent_Request_Limits#Rate_limits) for more information.

                '
              schema:
                type: integer
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/tokenResponse'
              example:
                access_token: c652cbc0ea384b9f81856a93a2a74538
                token_type: bearer
                expires_in: 3599
                scope: user.7c4d5433dc234c369a01b9719ecd059f entity.1a2b7a37-3e7d-4cb3-b0e2-883de9e766cc entity.c92ed977-510c-4c48-9b51-8d5e848671e9 service.echo.read tenant.19
                jti: c652cbc0ea384b9f81856a93a2a74539
        429:
          headers:
            Zuora-Request-Id:
              description: 'The Zuora internal identifier of the API call. You cannot control the value of this header.

                '
              schema:
                type: string
                maxLength: 36
                minLength: 36
            Zuora-Track-Id:
              description: 'A custom identifier for tracing the API call. If you specified a tracing identifier in the request headers, Zuora returns the same tracing identifier. Otherwise, Zuora does not set this header.

                '
              schema:
                type: string
                maxLength: 64
            X-RateLimit-Limit-minute:
              description: 'The rate limit of this operation, in requests per minute. See [rate limits](https://knowledgecenter.zuora.com/BB_Introducing_Z_Business/Policies/Concurrent_Request_Limits#Rate_limits) for more information.

                '
              schema:
                type: integer
            X-RateLimit-Remaining-minute:
              description: 'The number of requests that you may make in the next minute. See [rate limits](https://knowledgecenter.zuora.com/BB_Introducing_Z_Business/Policies/Concurrent_Request_Limits#Rate_limits) for more information.

                '
              schema:
                type: integer
          description: Too Many Requests
      x-code-samples:
      - lang: curl
        label: Curl
        source: 'curl -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "client_id=b64e42ba-7e1a-4bc6-9146-5e1b420306b5" --data-urlencode "client_secret=dOFENLWU193EEoEsWjPZrcjLKVr5OrN1HC9Kqg" -d "grant_type=client_credentials" "https://rest.zuora.com/oauth/token"

          '
      requestBody:
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              properties:
                client_id:
                  type: string
                  maxLength: 36
                  minLength: 36
                  description: 'The Client ID of the OAuth client.

                    '
                client_secret:
                  type: string
                  maxLength: 42
                  description: 'The Client Secret that was displayed when the OAuth client was created.

                    '
                grant_type:
                  type: string
                  enum:
                  - client_credentials
                  description: 'The OAuth grant type that will be used to generate the token. The value of this parameter must be `client_credentials`.

                    '
              required:
              - client_id
              - client_secret
              - grant_type
components:
  schemas:
    tokenResponse:
      properties:
        access_token:
          description: The generated token.
          type: string
        expires_in:
          description: The number of seconds until the token expires.
          type: number
        jti:
          description: A globally unique identifier for the token.
          type: string
        scope:
          description: A space-delimited list of scopes that the token can be used to access.
          type: string
        token_type:
          description: The type of token that was generated, i.e., `bearer`.
          type: string
      type: object
  parameters:
    GLOBAL_HEADER_Zuora_Track_Id:
      name: Zuora-Track-Id
      in: header
      required: false
      description: 'A custom identifier for tracing the API call. If you set a value for this header, Zuora returns the same value in the response headers. This header enables you to associate your system process identifiers with Zuora API calls, to assist with troubleshooting in the event of an issue.


        The value of this field must use the US-ASCII character set and must not include any of the following characters: colon (`:`), semicolon (`;`), double quote (`"`), and quote (`''`).

        '
      schema:
        type: string
        maxLength: 64
x-tagGroups:
- name: Authentication
  tags:
  - OAuth
- name: Products
  tags:
  - Products
  - Catalog
  - Catalog Groups
  - Offers
  - Price Book Items
  - Product Rate Plans
  - Product Rate Plan Definitions
  - Product Rate Plan Charges
  - Product Charge Definitions
  - Product Rate Plan Charge Tiers
  - Zuora Revenue Integration
- name: Customer Accounts
  tags:
  - Accounts
  - Contacts
  - Contact Snapshots
- name: Orders and Subscriptions
  tags:
  - Sign Up
  - Orders
  - Order Actions
  - Order Line Items
  - Fulfillments
  - Ramps
  - Subscriptions
  - Rate Plans
- name: Advanced Consumption Billing
  tags:
  - Prepaid with Drawdown
- name: Usage
  tags:
  - Usage
- name: Billing Documents
  tags:
  - Delivery Adjustments
  - Billing Documents
  - Invoices
  - Credit Memos
  - Debit Memos
  - E-Invoicing
  - Invoice Schedules
  - Taxation Items
  - Sequence Sets
  - Operations
- name: Bill Runs
  tags:
  - Bill Run
  - Billing Preview Run
- name: Payment Methods
  tags:
  - Payment Methods
  - Custom Payment Method Types
  - Payment Method Updater
  - Payment Method Snapshots
  - Payment Method Transaction Logs
  - Hosted Pages
  - RSA Signatures
- name: Payments
  tags:
  - Payment Authorization
  - Payment Gateways
  - Payment Gateway Reconciliation
  - Payments
  - Payment Transaction Logs
  - Payment Runs
  - Payment Schedules
  - Refunds
- name: Finance
  tags:
  - Accounting Codes
  - Accounting Periods
  - Summary Journal Entries
  - Journal Runs
  - Mass Updater
- name: Events and Notifications
  tags:
  - Notifications
  - Custom Event Triggers
  - Custom Scheduled Events
- name: Custom Objects
  tags:
  - Custom Object Definitions
  - Custom Object Records
  - Custom Object Jobs
- name: System Health
  tags:
  - API Health
  - Bill Run Health
  - Electronic Payments Health
- name: Workflow
  tags:
  - Workflows
- name: Data Query
  tags:
  - Data Queries
- name: AQuA
  tags:
  - Aggregate Queries
- name: Deployment Manager
  tags:
  - Configuration Templates
- name: Multiple Organizations
  tags:
  - Data Labeling
- name: Order to Revenue
  tags:
  - Regenerate
- name: General-Purpose Operations
  tags:
  - Actions
  - Settings
  - Files
  - Imports
  - Custom Exchange Rates
  - Attachments
  - Describe