> **Building with AI coding agents?** Install the authstack plugin with one command. This equips your agent with accurate Scalekit implementation patterns.
>
> **Recommended**:
> ```bash
> npx @scalekit-inc/cli setup
> ```
>
> Global:
> ```bash
> npm install -g @scalekit-inc/cli
> scalekit setup
> ```
>
> Supports Claude Code, Cursor, GitHub Copilot, Codex + skills for other Agent Skills-compatible agents.
> Skills: integrate-agentkit, implement-saaskit, add-mcp-oauth, implement-sso, implement-scim.
> [Full setup guide](https://docs.scalekit.com/dev-kit/build-with-ai/)

---

# Authentication

AgentKit uses the OAuth 2.0 client credentials grant. Exchange your client ID and secret for an access token, then send the token on every request: `Authorization: Bearer <access_token>`.

## Get your credentials

Each environment has its own environment URL, client ID and client secret, under **Developers** > **Settings** > **API Credentials**. See [API credentials](https://docs.scalekit.com/agentkit/api-credentials/) to generate and rotate a secret.

## Request a token

POST to `/oauth/token` on your environment URL with `grant_type=client_credentials`. The response has `access_token`, `token_type` and `expires_in`, in seconds. The SDK clients get the token for you.

## When a call returns 401

Read `error_code` in the error body to tell the two causes apart:

- **`UNAUTHENTICATED`**: your access token is missing, invalid or expired. Get a new token and retry. The SDK clients do this for you.
- **`TOOL_ERROR`** with `tool_error_code` `REAUTHENTICATION_NEEDED`, or `UNAUTHENTICATED` when the connected account is `EXPIRED`: the user's access to the app was revoked or expired. A new token won't help: the user must authorize again, so send them a new [authorization link](https://docs.scalekit.com/agentkit/reference/authorization/get-an-authorization-link/). See [Errors and rate limits](https://docs.scalekit.com/agentkit/reference/errors/).

## Keep the secret on your server

Call the API from your backend only. Never put the client secret in browser or mobile code, or in an agent's prompt or tool output.

## Acting as a user

The token identifies your environment, not an end user. Endpoints that act for a user take `identifier`, your ID for that user, or a `connected_account_id`. See [Connected accounts](https://docs.scalekit.com/agentkit/reference/connected-accounts/).

## Examples

### Request a token

REST:

```bash
TOKEN=$(curl -sS "$SCALEKIT_ENVIRONMENT_URL/oauth/token" \
  -d grant_type=client_credentials \
  -d client_id="$SCALEKIT_CLIENT_ID" \
  -d client_secret="$SCALEKIT_CLIENT_SECRET" | jq -r .access_token)
```

Python:

```python
import os
from scalekit import ScalekitClient

scalekit_client = ScalekitClient(
    env_url=os.environ["SCALEKIT_ENVIRONMENT_URL"],
    client_id=os.environ["SCALEKIT_CLIENT_ID"],
    client_secret=os.environ["SCALEKIT_CLIENT_SECRET"],
)
actions = scalekit_client.actions
```

Node.js:

```ts
import { ScalekitClient } from '@scalekit-sdk/node';

const scalekit = new ScalekitClient(
  process.env.SCALEKIT_ENVIRONMENT_URL!,
  process.env.SCALEKIT_CLIENT_ID!,
  process.env.SCALEKIT_CLIENT_SECRET!,
);
const actions = scalekit.actions;
```

### Use it

```bash
curl -sS "$SCALEKIT_ENVIRONMENT_URL/api/v1/tools" \
  -H "Authorization: Bearer $TOKEN"
```

Next: [Errors and rate limits](https://docs.scalekit.com/agentkit/reference/errors.md)


---

## More Scalekit documentation

| Resource | What it contains | When to use it |
|----------|-----------------|----------------|
| [/llms.txt](/llms.txt) | Structured index with routing hints per product area | Start here — find which documentation set covers your topic before loading full content |
| [/llms-full.txt](/llms-full.txt) | Complete documentation for all Scalekit products in one file | Use when you need exhaustive context across multiple products or when the topic spans several areas |
| [sitemap-0.xml](https://docs.scalekit.com/sitemap-0.xml) | Full URL list of every documentation page | Use to discover specific page URLs you can fetch for targeted, page-level answers |
