curl --request POST \
--url https://oauth2-{dc}.moengage.com/v1/oauth/token \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=client_credentials \
--data client_id=YOUR_WORKSPACE_ID \
--data client_secret=YOUR_API_KEY{
"status": "SUCCESS",
"data": {
"access_token": "eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjoiUlN3Q2t6...",
"refresh_token": "550e8400-e29b-41d4-a716-446655440000",
"token_type": "Bearer",
"expires_in": 900
}
}{
"status": "FAILURE",
"error_type": "ER019",
"reason": "client_id is required."
}{
"status": "FAILURE",
"error_type": "ER011",
"reason": "Auth validation failed."
}{
"status": "FAILURE",
"error_type": "<string>",
"reason": "<string>"
}{
"status": "FAILURE",
"error_type": "RATE_LIMIT_EXCEEDED",
"reason": "Too many requests."
}Generate Access Token
Exchange the client_id and client_secret of an OAuth 2.0 API key for an access token and a refresh token.
The client_id is your Workspace ID, and the client_secret is the API key value that the dashboard displays once, when you create the key. The key must have Authentication Type set to OAuth 2.0 on the API key dashboard, or the request fails with ER012.
To create the key, refer to API Key Dashboard. For the end-to-end integration, refer to OAuth 2.0 Overview. To renew an access token without resending your API key, refer to Refresh Access Token.
curl --request POST \
--url https://oauth2-{dc}.moengage.com/v1/oauth/token \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=client_credentials \
--data client_id=YOUR_WORKSPACE_ID \
--data client_secret=YOUR_API_KEY{
"status": "SUCCESS",
"data": {
"access_token": "eyJhbGciOiJSUzI1NiJ9.eyJkYXRhIjoiUlN3Q2t6...",
"refresh_token": "550e8400-e29b-41d4-a716-446655440000",
"token_type": "Bearer",
"expires_in": 900
}
}{
"status": "FAILURE",
"error_type": "ER019",
"reason": "client_id is required."
}{
"status": "FAILURE",
"error_type": "ER011",
"reason": "Auth validation failed."
}{
"status": "FAILURE",
"error_type": "<string>",
"reason": "<string>"
}{
"status": "FAILURE",
"error_type": "RATE_LIMIT_EXCEEDED",
"reason": "Too many requests."
}Rate Limit
This endpoint allows 30 requests per 10 minutes and 5 requests per minute. Both limits apply perclient_id and client_secret pair. A 429 response includes a Retry-After header that gives the number of seconds to wait.
Access tokens are reusable for their full lifetime. Generate one access token and reuse the token until the token approaches expiry, instead of calling this endpoint for every API request.
Determine the Token Expiry
Theexpires_in field gives the access token’s lifetime in seconds, counted from the moment MoEngage issues the token. Schedule your refresh from that value. The lifetime reflects the Access token expiration (in minutes) set on the API key, which defaults to 15 minutes.
Send the access token on API requests as Authorization: Bearer <access_token>. For the request format and the authentication error codes, refer to Call the MoEngage Public APIs.Body
The form-encoded credentials for the client credentials grant.
The OAuth 2.0 grant type. The supported value is client_credentials.
client_credentials Your Workspace ID. The API key dashboard displays the Workspace ID at Settings > Account > API keys.
The API key value. The dashboard displays the API key only once, when you create the key.