To interact with our APIs securely, you must authenticate using OAuth2 Client Credentials Flow.
Steps
- Request tokens: From the authorized application, request an access token for your API.
- Call API: Use the retrieved access token to call your API.
Request tokens
To access your API, you must request an access token for it. To do so, you will need to POST to the token URL.
| Environment | URL |
|---|---|
| Production | https://connect.xpollens.com/connect/token |
| Sandbox | https://sb-connect.xpollens.com/connect/token |
Request Parameters
| Parameter | Value |
|---|---|
grant_type | client_credentials |
client_id | Your client ID |
client_secret | Your client secret |
scope | partner |
Example (cURL)
curl -X POST https://sb-connect.xpollens.com/connect/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials" \
-d "client_id=YOUR_CLIENT_ID" \
-d "client_secret=YOUR_CLIENT_SECRET" \
-d "scope=partner"
Sample Response
{
"access_token": "eyJhbGciOiJIUzI1NiIsInR...",
"expires_in": 3600,
"token_type": "Bearer"
}
Call API
To call your API from the M2M application, the application must pass the retrieved access token as a Bearer token in the Authorization header of your HTTP request.
Example (cURL)
curl --request GET \
--url https://sb-api.xpollens.com/api/XXXXXXX \
--header 'authorization: Bearer ACCESS_TOKEN' \
--header 'content-type: application/json'
Get more information about Client Credentials Flow
Connect/token ratelimit
June 2026
The limit is fixed to 15 requests per minute per IP address. This measure is intended to ensure the stability, security, and performance of our entire ecosystem.
We strongly recommend that you reuse existing tokens rather than generating a new one for each call.
Anti-brute force
If you fail multiple times while attempting to retrieve a token using invalid credentials, you will receive error code 423 Locked and your IP address will be blocked.