Authentication
All new Caspeco APIs use OAuth 2.0 Client Credentials flow for authentication. This guide shows you how to obtain and use access tokens for API requests.
Prerequisites
Section titled “Prerequisites”Before you begin, make sure you have:
- A Caspeco developer account
- A Client ID and Client Secret from the Integrations page
Getting an Access Token
Section titled “Getting an Access Token”To authenticate, send a POST request to the token endpoint with your credentials:
POST https://id.caspeco.se/connect/tokenContent-Type: application/x-www-form-urlencoded
grant_type=client_credentialsclient_id=YOUR_CLIENT_IDclient_secret=YOUR_CLIENT_SECRETscope=publicAPIResponse
Section titled “Response”You’ll receive a JSON response containing your access token:
{ "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...", "token_type": "Bearer", "expires_in": 600, "scope": "publicAPI"}The access_token is valid for the duration specified by expires_in (in seconds). Cache and reuse the token until it expires to minimize authentication requests.
Using the Access Token
Section titled “Using the Access Token”Include the access token in the Authorization header of your API requests:
GET https://api.caspeco.com/api/../v1/endpointAuthorization: Bearer YOUR_ACCESS_TOKENBest Practices
Section titled “Best Practices”- Store credentials securely - Never expose Client Secrets in client-side code or public repositories
- Cache tokens - Reuse access tokens until they expire instead of requesting a new token for each API call
- Handle expiration - When the access token expires or you receive a 401 Unauthorized response due to expiration, request a new access token using the client credentials