Authenticate your backend

This guide covers machine-to-machine (M2M) authentication between your backend and the Repset Integration API. Your backend authenticates itself. Requests that act on behalf of a user takes in a user_id in the URL.

Prerequisites

  • A developer account.
  • A client created in the console. You will need a client_id and client_secret for the rest of this guide.

Fetching an access token

You need an access token to call the API. Get one with the OAuth2 client_credentials grant. See the examples below, and adapt them to your stack.

Tokens are short-lived so fetch a new one per request. Reusing a token is fine for requests made in quick succession.

curl
openid-client
fetch-token.sh
curl https://auth.repset.io/realms/repset/protocol/openid-connect/token \
  --request POST \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'grant_type=client_credentials' \
  --data-urlencode 'client_id={clientId}' \
  --data-urlencode 'client_secret={clientSecret}'
response.json
{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJ...",
  ...
}
fetch-token.ts
import * as client from "openid-client";

const config = await client.discovery(
  new URL("https://auth.repset.io/realms/repset"),
  process.env.REPSET_CLIENT_ID,
  process.env.REPSET_CLIENT_SECRET,
);

const tokens = await client.clientCredentialsGrant(config);
console.log(tokens.access_token);

Authenticating requests

Send the access token as a Bearer token in the Authorization header.

authenticated-request-example.sh
curl https://integration-api.repset.io/api/v1/users/{userId} \
  --header "Authorization: Bearer {accessToken}"

Next steps

Most endpoints are scoped to a user as well as a client. See User Authentication for how to connect a Repset user to your integration.