Get started

This guide covers machine-to-machine (m2m) authentication between your backend and the Repset integration-api. The integration is authenticating itself, not your users. Even requests that act on behalf of a user go through these same client credentials. It’s always your backend authenticating, the user is just referenced by a user-id in the request.

Prerequisites

  • A developer account.
  • A client created in the console. You will need a client_id and client_secret for the rest of this guide.

Authenticating requests

Authenticate every request with HTTP Basic Auth, using client_id as the username and client_secret as the password.

authenticated-request-example.sh
curl https://integration-api.repset.io/api/v1/users/{userId} \
  -u client_id:client_secret
Changes to auth

We’re moving towards an OAuth2 client_credentials grant with short-lived access tokens, replacing Basic Auth for m2m requests. More info will come before the migration.

Next steps

Most endpoints are scoped to a user as well as a client. See User authentication for how to connect a Repset user to your integration.