Skip to content

Authenticate ​

All Engine API calls require a Bearer token issued by the Identity API.

Set up your environment ​

The rest of this guide assumes the following environment variables are exported. Replace the placeholders with the values from your account manager and the portal.

bash
export KUSTODYAN_IDENTITY_URL=https://<env>.kustodyan.io/api/identity
export KUSTODYAN_ENGINE_URL=https://<env>.kustodyan.io/api/engine
export KUSTODYAN_CLIENT_ID=...
export KUSTODYAN_CLIENT_SECRET=...

TIP

Store credentials in a secrets manager. Do not commit them to version control.

Get a Bearer token ​

Exchange your client credentials at the Identity API.

bash
curl -s -X POST "$KUSTODYAN_IDENTITY_URL/connect/token" \
  -d "grant_type=client_credentials" \
  -d "client_id=$KUSTODYAN_CLIENT_ID" \
  -d "client_secret=$KUSTODYAN_CLIENT_SECRET"

A successful response:

json
{
  "access_token": "eyJhbGciOiJSUzI1NiIs...",
  "expires_in": 1800,
  "token_type": "Bearer",
  "scope": "rps_engine_api"
}

Tokens last 30 minutes by default. Cache them in your application and refresh just before expiry. The full endpoint reference is in API Reference › Authentication.

Send the token ​

On every Engine API call, send the token in the Authorization header:

http
Authorization: Bearer <access_token>