Skip to content

Authentication

The Worklayer API uses an OAuth client credentials flow to authenticate requests. API client keys are currently provisioned on demand for your workspace. You can request API keys for your workspace by contacting our customer success team.

Your API client is associated with a machine-type member in your workspace, and permissions can be granted to that member to allow or restrict specific flows.

Be sure to keep your API keys secure and not share them in publicly accessible areas such as GitHub, client-side code, and so forth.

Authentication with the API is performed by requesting a token with your client and passing that token via an Authorization header as a Bearer token in the request.

All API requests must be made over HTTPS. Calls made over plain HTTP might fail. Likewise, API requests without authentication will also fail.

Retrieving a token

Request Parameters

client_id
•
string
required

Your client ID.

client_secret
•
string
required

Your client secret.

audience
•
string
required

The audience of the token. Only https://api.worklayer.com/public/ is supported, regardless of environment.

grant_type
•
string
required

Only client_credentials is supported.

Sample Request

bash
Copied
1curl -X POST "https://api.worklayer.com/oauth/token" \
2 -H 'content-type: application/json' \
3 -d '{"client_id":"{your_client_id}","client_secret":"{your_client_secret}","audience":"https://api.worklayer.com/public/","grant_type":"client_credentials"}'

Response

access_token
•
string

The access token.

scope
•
string

The scope of the token. Usually, api:access.

expires_in
•
number

The number of seconds until the token expires.

token_type
•
string

The type of token. Always Bearer.

json
Copied
1{
2 "access_token": "eyJhbGciOiJSUzI1NiIsIn...",
3 "scope": "api:access",
4 "expires_in": 3600,
5 "token_type": "Bearer"
6}

Authenticating a request

Here we show calling the member list endpoint with a token.

bash
Copied
1curl -X GET 'https://api.worklayer.com/v1.0/members' \
2-H 'Authorization: Bearer {access_token}'

Errors

The token endpoint does not use the error body described in Error Handling. Instead, it follows the OAuth 2.0 error format from RFC 6749 section 5.2.

Error Response

error
•
string

The OAuth error code. See the table below.

error_description
•
string

A human-readable description of the error.

json
Copied
1{
2 "error": "invalid_client",
3 "error_description": "Invalid client credentials"
4}
Status codeerrorWhen it happens
400invalid_requestA required parameter is missing or malformed. The description names the parameter.
400unsupported_grant_typegrant_type is not client_credentials.
400invalid_targetaudience is not https://api.worklayer.com/public/.
400authorization_pendingThe client is still being provisioned. Try again shortly.
401invalid_clientThe client_id or client_secret is wrong.
500server_errorThe authorization server encountered an unexpected error. Retry with backoff.

Requests to any other endpoint with a missing, invalid, or expired token return a 401 response with the standard error body.


Last updated on October 2, 2026