Skip to main content
Provider-scoped endpoints can be used from a client app with a short-lived scoped auth token instead of your API key.

Generate a token

From your backend, call the Generate Scoped Auth Token endpoint with the origin of your client app and the Provider ID. The returned scoped_token is valid for one hour.
Generate scoped auth token
To call Create provider source or Test new provider source, also include the source in the token request. Those requests must send the same source.

Call an endpoint

List provider sources
  • X-APP-ID is any single identifier for your client app, with no spaces. The React SDK sends third-party-client.
  • Origin is set by the browser. Its hostname must match the hostname of application_origin. Browser requests also require that origin on your organization’s CORS allowlist.
  • The provider_id in the path must match the token.