> ## Documentation Index
> Fetch the complete documentation index at: https://docs.prequel.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Provider-scoped endpoints

> Endpoints that restrict every request to a single Provider.

Provider-scoped endpoints can be used from a client app with a short-lived scoped auth token instead of your API key.

## Generate a token

From your backend, call the [Generate Scoped Auth Token endpoint](/import/api-reference/auth/generate-scoped-auth-token) with the origin of your client app and the Provider ID. The returned `scoped_token` is valid for one hour.

```bash title="Generate scoped auth token" icon="terminal" expandable theme={null}
curl --request POST https://api.prequel.co/import/actions/generate-scoped-auth-token \
  --header "X-API-KEY: <api_key>" \
  --header "Content-Type: application/json" \
  --data '{
    "application_origin": "https://app.acme.com",
    "provider_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
  }'
```

To call [Create provider source](/import/api-reference/provider-scoped/sources/create-provider-source) or [Test new provider source](/import/api-reference/provider-scoped/sources/test-new-provider-source), also include the `source` in the token request. Those requests must send the same `source`.

## Call an endpoint

```bash title="List provider sources" icon="terminal" theme={null}
curl https://api.prequel.co/import/providers/3fa85f64-5717-4562-b3fc-2c963f66afa6/sources \
  --header "Authorization: Bearer <scoped_token>" \
  --header "X-APP-ID: acme-import" \
  --header "Origin: https://app.acme.com"
```

* `X-APP-ID` is any single identifier for your client app, with no spaces. The React SDK sends `third-party-client`.
* `Origin` is set by the browser. Its hostname must match the hostname of `application_origin`. Browser requests also require that origin on your organization's CORS allowlist.
* The `provider_id` in the path must match the token.
