> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.upwardli.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.upwardli.com/_mcp/server.

# Oauth 2.0 Authentication

This page describes how to request an authentication token. These authentication tokens are used for machine to machine communication.

## Scopes

| Scope                      | Use                                                                                                                    |
| -------------------------- | ---------------------------------------------------------------------------------------------------------------------- |
| `api:read`                 | Perform read-only operations for machine to machine (M2M) scenrarios.                                                  |
| `api:write`                | Perform full CRUD operations for machine to machine (M2M) scenrarios.                                                  |
| `ui:client-onboarding`     | Used for the [Onboarding Client Component](/ui-components/onboarding) in combination with `api:read` and `api:write`   |
| `api:credit-insights:read` | Access to Read [Credit Insights](/api-access/api-reference/credit-insights/retrieve-credit-insights-overview-v-2) data |
| `api:profile:read`         | Access to Read [Profile](/api-access/api-reference/consumers/retrieve-consumer) data                                   |
| `api:trade-line:read`      | Access to Read [Credit Line](/api-access/api-reference/credit-lines/retrieve-get-credit-line) data                     |
| `api:rewards:read`         | Access to Read [Cashback Rewards](/guides/cashback-rewards) configurations, enrollments, and offers                    |
| `api:rewards:write`        | Access to enroll a card in [Cashback Rewards](/guides/cashback-rewards)                                                |

## Requesting Tokens Using The API

The Upward API OAuth 2.0 for authentication and authorization. Before you can use the API, you must obtain an access token using the client\_id and client\_secret provided to you. Once a token has been obtained, it must be passed in the Authorization header of each request to the API.

To request a token send a POST to our auth server containing the client ID and client secret provided.

## Onboarding Token Request

POST [https://auth-sandbox.upwardli.com/auth/token/](https://auth-sandbox.upwardli.com/auth/token/)

```json
{
"header": "content-type: application/json",
"grant_type":"client_credentials",
"client_id":"[your id here]",
"client_secret":"[your secret here]",
"scope":"api:read api:write ui:client-onboarding"
}
```

### Here's a cURL example for the token request:

```cmd
curl --location --request POST https://auth-sandbox.upwardli.com/auth/token/ \
--header 'Content-Type: application/json' \
--data \
'{
  "grant_type":"client_credentials", 
  "client_id":"[api client key]", 
  "client_secret":"[api client secret]", 
  "scope":"api:read api:write ui:client-onboarding" 
}'
```

### Here's what a successful response looks like:

```json
{
    "access_token": "xxxxx",
    "expires_in": 86400,
    "token_type": "Bearer",
    "scope": "api:read api:write ui:client-onboarding"
}
```