Skip to content
Scalekit Docs
Talk to an Engineer Dashboard

Authentication

AgentKit uses the OAuth 2.0 client credentials grant. Exchange your client ID and secret for an access token, then send the token on every request: Authorization: Bearer <access_token>.

Get your credentials

Each environment has its own environment URL, client ID and client secret, under Developers > Settings > API Credentials. See API credentials to generate and rotate a secret.

Request a token

POST to /oauth/token on your environment URL with grant_type=client_credentials. The response has access_token, token_type and expires_in, in seconds. The SDK clients get the token for you.

When a call returns 401

Read error_code in the error body to tell the two causes apart:

  • UNAUTHENTICATED: your access token is missing, invalid or expired. Get a new token and retry. The SDK clients do this for you.
  • TOOL_ERROR with tool_error_code REAUTHENTICATION_NEEDED, or UNAUTHENTICATED when the connected account is EXPIRED: the user's access to the app was revoked or expired. A new token won't help: the user must authorize again, so send them a new authorization link. See Errors and rate limits.

Keep the secret on your server

Call the API from your backend only. Never put the client secret in browser or mobile code, or in an agent's prompt or tool output.

Acting as a user

The token identifies your environment, not an end user. Endpoints that act for a user take identifier, your ID for that user, or a connected_account_id. See Connected accounts.