Entur Developer
Sales v2

authentication

Server

Authentication endpoints for issuing OAuth tokens.


Issue OAuth access token

POST
https://api.entur.io/omsa/v1
/oauth/token

This endpoint is used to obtain an access token and optionally an ID token through different OAuth 2.0 grant types, including Client Credentials Flow. Whenever the mTLS flow is taken, the properties will be ignored, and the access token will be generated based on the credentials in the certificate (O or CN).

Issue OAuth access token › Headers

ET-Client-Name
​string · style: simple

Entur Client Header. It is required that all consumers identify themselves by using this header. Entur will deploy strict rate-limiting policies on API-consumers who do not identify with a header and reserves the right to block unidentified consumers. The structure of ET-Client-Name should be: <company>-<application>.

X-Correlation-Id
​string · style: simple

Correlation id

Issue OAuth access token › Request Body

grant_type
​string · enum · required

The grant type: 'client_credentials', 'password', or 'refresh_token'.

Enum values:
client_credentials
password
refresh_token
Default: client_credentials
username
​string

The username

password
​string

The password

client_id
​string

The client ID (Client Credentials Flow)

client_secret
​string

The client secret (Client Credentials Flow)

Issue OAuth access token › Responses

Successful token issuance.

access_token
​string

The issued access token.

refresh_token
​string

The optional refresh token.

token_type
​string

The type of the token.

Default: Bearer
expires_in
​integer

The lifetime of the access token in seconds.


Did you find what you were looking for?