Generate a token
From your backend, call the Generate Scoped Auth Token endpoint with the origin of your client app and the Provider ID. The returnedscoped_token is valid for one hour.
Generate scoped auth token
source in the token request. Those requests must send the same source.
Call an endpoint
List provider sources
X-APP-IDis any single identifier for your client app, with no spaces. The React SDK sendsthird-party-client.Originis set by the browser. Its hostname must match the hostname ofapplication_origin. Browser requests also require that origin on your organization’s CORS allowlist.- The
provider_idin the path must match the token.