Skip to content

Authentication

All new Caspeco APIs use OAuth 2.0 Client Credentials flow for authentication. This guide shows you how to obtain and use access tokens for API requests.

Before you begin, make sure you have:

  • A Caspeco developer account
  • A Client ID and Client Secret from the Integrations page

To authenticate, send a POST request to the token endpoint with your credentials:

POST https://id.caspeco.se/connect/token
Content-Type: application/x-www-form-urlencoded
grant_type=client_credentials
client_id=YOUR_CLIENT_ID
client_secret=YOUR_CLIENT_SECRET
scope=publicAPI

You’ll receive a JSON response containing your access token:

{
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"token_type": "Bearer",
"expires_in": 600,
"scope": "publicAPI"
}

The access_token is valid for the duration specified by expires_in (in seconds). Cache and reuse the token until it expires to minimize authentication requests.

Include the access token in the Authorization header of your API requests:

GET https://api.caspeco.com/api/../v1/endpoint
Authorization: Bearer YOUR_ACCESS_TOKEN
  • Store credentials securely - Never expose Client Secrets in client-side code or public repositories
  • Cache tokens - Reuse access tokens until they expire instead of requesting a new token for each API call
  • Handle expiration - When the access token expires or you receive a 401 Unauthorized response due to expiration, request a new access token using the client credentials