OAuth

Create an OAuth token

Creates a bearer token that enables an OAuth client to authenticate with the Zuora REST API. The OAuth client must have been created using the Zuora UI. See Authentication for more information.

Note: When using this operation, do not set any authentication headers such as Authorization, apiAccessKeyId, or apiSecretAccessKey.

You should not use this operation to generate a large number of bearer tokens in a short period of time; each token should be used until it expires. If you receive a 429 Too Many Requests response when using this operation, reduce the frequency of requests. This endpoint is rate limited by IP address.

For the rate limit information of authentication, see Rate and concurrent request limits.

post/oauth/token

Headers

Zuora-Track-Idstring

A custom identifier for tracing the API call. If you set a value for this header, Zuora returns the same value in the response headers. This header enables you to associate your system process identifiers with Zuora API calls, to assist with troubleshooting in the event of an issue.

The value of this field must use the US-ASCII character set and must not include any of the following characters: colon (:), semicolon (;), double quote ("), and quote (').

Zuora-Entity-Idsstring uuid
Example:11e643f4-a3ee-8bad-b061-0025904c756d

An entity ID if you have <a href="https://docs.zuora.com?resourceId=platform-multi-entity-overview" target="_blank">Multi-entity</a> enabled.

The value must be a 36-character UUID that contains hyphens(-). If your entity ID is not a valid UUID, convert it to a valid UUID before specifying this parameter.

Response

OK

access_tokenstring

The generated token.

expires_innumber

The number of seconds until the token expires.

jtistring

A globally unique identifier for the token.

scopestring

A space-delimited list of scopes that the token can be used to access.

token_typestring

The type of token that was generated, i.e., bearer.

Changes