Authentication
AgentKit uses the OAuth 2.0 client credentials grant. Exchange your client ID and secret for an access token, then send the token on every request: Authorization: Bearer <access_token>.
Get your credentials
Each environment has its own environment URL, client ID and client secret, under Developers > Settings > API Credentials. See API credentials to generate and rotate a secret.
Request a token
POST to /oauth/token on your environment URL with grant_type=client_credentials. The response has access_token, token_type and expires_in, in seconds. The SDK clients get the token for you.
When a call returns 401
Read error_code in the error body to tell the two causes apart:
UNAUTHENTICATED: your access token is missing, invalid or expired. Get a new token and retry. The SDK clients do this for you.TOOL_ERRORwithtool_error_codeREAUTHENTICATION_NEEDED, orUNAUTHENTICATEDwhen the connected account isEXPIRED: the user's access to the app was revoked or expired. A new token won't help: the user must authorize again, so send them a new authorization link. See Errors and rate limits.
Keep the secret on your server
Call the API from your backend only. Never put the client secret in browser or mobile code, or in an agent's prompt or tool output.
Acting as a user
The token identifies your environment, not an end user. Endpoints that act for a user take identifier, your ID for that user, or a connected_account_id. See Connected accounts.