Managed-account OAuth Clients use the OAuth 2.0 Client Credentials flow. They are different from partner apps. If you build a partner app that operators authorise themselves, or prepare an app for marketplace distribution, follow Building a partner integration and use Authorization Code instead.
Connect a Stora account
Before creating credentials for a real account, follow Connect an account to generate an invitation and get staff approval. Then open the active account under Connected accounts in the Developer Portal. To explore without real account data, create a test operator first.Choose Access Tokens or OAuth Clients
Both options authenticate requests withAuthorization: Bearer <token>. The difference is how you obtain and renew the token.
Access Tokens expire. Use them for one-time scripts or short-lived tasks performed by an AI agent, where you need to make requests without implementing a token exchange. Once a token expires, it no longer authenticates requests. Use OAuth Clients instead for ongoing integrations so your backend can obtain new tokens automatically.
For AI-agent tasks, select only the scopes the task needs and the shortest suitable token lifetime. Supply the token through protected runtime configuration, not in a prompt, and revoke it when the task is finished.
Use OAuth Clients for an ongoing integration where your backend can obtain and renew tokens automatically. Short-lived tokens limit how long a leaked access token remains usable, but you must still protect the client secret: anyone with it can request new tokens.
Use an Access Token
- Open the connected account and click New access token under Access tokens.
- Enter a Name, select the scopes you need, and choose an Expires value.
- Click Create access token and copy the token immediately. You cannot view it again.
- Use it directly as the bearer token in your first API request.
Use an OAuth Client
Client Credentials is a server-to-server flow. After creating the client in the portal, your backend can request tokens without a browser redirect, callback URL, or interactive Stora login.1. Create the OAuth Client
- Open the account under Connected accounts.
- Under OAuth clients, click New OAuth client.
- Enter a Name that identifies your integration, such as
Reporting sync. - Select only the scopes your integration needs. For the example below, select
public.site:read. - Click Create OAuth client.
- Copy the Client ID and Client secret, then click Done.
2. Exchange the credentials for an access token
Send a JSON request toPOST https://public-api.stora.co/oauth2/token. Replace YOUR_CLIENT_ID and YOUR_CLIENT_SECRET with the credentials you copied.
grant_typemust beclient_credentials.client_idandclient_secretidentify and authenticate the OAuth Client.scopeis required. Use a space-separated list of scopes enabled for the client, such aspublic.site:read public.contact:read.
/2025-09 to its URL.
An example successful response:
access_token for API requests. expires_in is the token lifetime in seconds: 7200 means 2 hours. The response’s scope tells you which permissions the token has.
3. Call the API with the issued token
ReplaceYOUR_ISSUED_ACCESS_TOKEN with the access_token from the response:
The bearer token is the issued
access_token, not the client ID or client secret. Both portal-created Access Tokens and OAuth-issued access tokens use the same bearer header.4. Obtain a new token before expiry
Store the token and its expiry securely on your backend. Reuse the token for API calls rather than requesting a new one for every call. Before the token expires, repeat the request in step 2 with the same client ID, client secret, and required scopes. For example, request a replacement 5 minutes before expiry. Use the newaccess_token in subsequent API requests.
Client Credentials does not issue a refresh token. Do not use grant_type: refresh_token for these OAuth Clients. Renew access by repeating the client_credentials exchange.
Troubleshoot authentication
See Authorization for available scopes and Errors for API error responses.