API Authentication

To interact with our APIs securely, you must authenticate using OAuth2 Client Credentials Flow.

Steps

  1. Request tokens: From the authorized application, request an access token for your API.
  2. Call API: Use the retrieved access token to call your API.

Request tokens

To access your API, you must request an access token for it. To do so, you will need to POST to the token URL.


Request Parameters

ParameterValue
grant_typeclient_credentials
client_idYour client ID
client_secretYour client secret
scopepartner

Example (cURL)

curl -X POST https://sb-connect.xpollens.com/connect/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials" \
  -d "client_id=YOUR_CLIENT_ID" \
  -d "client_secret=YOUR_CLIENT_SECRET" \
  -d "scope=partner"

Sample Response

{
  "access_token": "eyJhbGciOiJIUzI1NiIsInR...",
  "expires_in": 3600,
  "token_type": "Bearer"
}

Call API

To call your API from the M2M application, the application must pass the retrieved access token as a Bearer token in the Authorization header of your HTTP request.

Example (cURL)

curl --request GET \
  --url https://sb-api.xpollens.com/api/XXXXXXX \
  --header 'authorization: Bearer ACCESS_TOKEN' \
  --header 'content-type: application/json'
📘

Get more information about Client Credentials Flow





Connect/token ratelimit

June 2026

The limit is fixed to 15 requests per minute per IP address. This measure is intended to ensure the stability, security, and performance of our entire ecosystem.

We strongly recommend that you reuse existing tokens rather than generating a new one for each call.





Anti-brute force

If you fail multiple times while attempting to retrieve a token using invalid credentials, you will receive error code 423 Locked and your IP address will be blocked.