Skip to main content
The Directory and DataExport APIs use OAuth 2.0 with the Client Credentials flow. This flow is designed for server-to-server communication where no end-user context is required — your application authenticates directly using its client credentials to obtain a short-lived access token.

Obtaining an access token

Send a POST request to the token endpoint with your client_id and client_secret:
The response contains the access token and its lifetime in seconds:

Using the access token

Include the token in the Authorization header of every API request:

Handling token expiry

Tokens are valid for the duration specified in expires_in (seconds). The Client Credentials flow does not issue refresh tokens — when your token expires, request a new one using the same client credentials.
Track expires_in in your application and proactively refresh the token before it expires to avoid failed requests.
If you are using the Directory API SDK, token refresh is handled automatically — you don’t need to manage token expiry yourself.