documentation /api provider

Bearer

API provider

Custom bearer-token authentication where the token is obtained by calling a token URL (POST with credentials, or GET) and parsing a field out of the response. For APIs that mint their own short-lived tokens.

  • API category: Generic
  • Needs login: No, two-legged: no end-user interaction is required

Configuration parameters

Required

  • title : string; required
    Human-readable label for this connection.
  • jwt_url : string; required
    URL to POST credentials to in order to obtain a bearer token.
  • method : string; required
    HTTP method for the token-issuance request. Use exactly POST (case-sensitive) to send post_body and credentials; any other value performs a credential-less GET.
  • post_body : string; required
    Body sent when method is POST (ignored for GET). May embed {{username}}/{{password}} placeholders and $ENV_VAR references, all substituted before sending. For POST with a non-empty username, the username and password are also sent as an HTTP Basic auth header.
  • username : string; required
    Username/client-id used in the token-issuance request.
  • password : string; required
    Password/secret used in the token-issuance request.
  • token_field : string; required
    Dot-separated path of JSON keys in the token-issuance response pointing at the bearer token (e.g. access_token or data.access_token). Leave blank if the response body is the token itself (surrounding double-quotes are stripped).
  • token_header : string; required
    Literal prefix prepended directly in front of the token to form the auth header, including the header name, : separator, and any scheme word and space (e.g. Authorization:Bearer yields Authorization:Bearer <token>). Nothing is added automatically.
  • expiry_seconds : string; required
    Seconds to cache the token before re-requesting it.

What components can use this API

Concepts:

Ingredients: