OAuth 2.0
Machine-to-machine authentication with the OAuth2 client-credentials grant. Create an OAuth credential in Account Settings, exchange it here for a short-lived access token, and send that token as Authorization: Bearer <access_token> on API calls. Tokens live 15 minutes and no refresh token is issued — a client that needs a fresh one repeats the exchange.
POSTExchange client credentials for an access token
OAuth 2.0 client-credentials grant (RFC 6749 §4.4). Credentials may be sent as HTTP Basic (`client_secret_basic`) or in the form body (`client_secret_post`). Responses are never cached.