> For the complete documentation index, see [llms.txt](https://docs.partssource.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.partssource.com/api/authentication/overview.md).

# Overview

Authenticate with the PartsSource APIs using OAuth 2.0

The PartsSource APIs use **JWT Bearer Token** authentication via **OAuth 2.0**. All API requests (except health checks) require a valid access token.

***

## Quick Start

### 1. Get an Access Token

```bash
curl -X POST https://auth.partssource.com/oauth2/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials" \
  -d "client_id=YOUR_CLIENT_ID" \
  -d "client_secret=YOUR_CLIENT_SECRET"
```

**Response:**

```json
{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
  "token_type": "Bearer",
  "expires_in": 3600
}
```

### 2. Use the Token

Include the token and API key in all requests:

```bash
curl -X GET "https://api.partssource.com/customer/api/users/lookup?userId=12345" \
  -H "Authorization: Bearer eyJhbGciOiJSUzI1NiIs..." \
  -H "x-api-key: YOUR_API_KEY"
```

***

## Authentication Flow

The APIs use the **OAuth 2.0 Client Credentials** flow, designed for machine-to-machine (M2M) integration:

```
Your Application                    Auth Server                      API
      |                                  |                            |
      |-- POST /oauth2/token ----------->|                            |
      |   (client_id, client_secret)     |                            |
      |                                  |                            |
      |<-- access_token -----------------|                            |
      |                                  |                            |
      |-- GET /api/resource ---------------------------------->|
      |   (Authorization: Bearer token)                        |
      |                                  |                            |
      |<-- Response -------------------------------------------|
```

***

## Token Details

| Property       | Value                 |
| -------------- | --------------------- |
| **Type**       | JWT (JSON Web Token)  |
| **Expiration** | 1 hour (3600 seconds) |
| **Algorithm**  | RS256                 |
| **Issuer**     | Authorization server  |

### Token Lifecycle

1. **Request** - Exchange credentials for access token
2. **Use** - Include token in API requests
3. **Refresh** - Request new token before expiration
4. **Expire** - Token becomes invalid after 1 hour

{% hint style="warning" %}
**Tokens expire after 1 hour.** Implement token refresh logic to avoid service interruption. See [Token Management](/api/authentication/oauth-2.0-flow/best-practices-and-error-handling.md) for best practices.
{% endhint %}

***

## Authentication Endpoints

| Endpoint      | URL                                                             | Purpose                          |
| ------------- | --------------------------------------------------------------- | -------------------------------- |
| **Token**     | `https://auth.partssource.com/oauth2/token`                     | Exchange credentials for token   |
| **JWKS**      | `https://auth.partssource.com/.well-known/jwks.json`            | Public keys for token validation |
| **Discovery** | `https://auth.partssource.com/.well-known/openid-configuration` | OpenID Connect configuration     |

***

## Error Responses

### 401 Unauthorized

Returned when authentication fails:

```json
{
  "type": "https://tools.ietf.org/html/rfc7235#section-3.1",
  "title": "Unauthorized",
  "status": 401,
  "detail": "Authentication is required to access this resource.",
  "correlationId": "0HN7QJKV3QJ8K:00000001"
}
```

**Common causes:**

* Missing `Authorization` header
* Invalid or malformed token
* Expired token
* Token signature validation failed

### 403 Forbidden

Returned when authentication succeeds but authorization fails:

```json
{
  "type": "https://tools.ietf.org/html/rfc7231#section-6.5.3",
  "title": "Forbidden",
  "status": 403,
  "detail": "You do not have permission to access this resource.",
  "correlationId": "0HN7QJKV3QJ8K:00000001"
}
```

**Common causes:**

* Attempting cross-tenant access (CustomerApi)
* User doesn't have facility access

***

## Next Steps

* [**Obtaining Tokens**](/api/authentication/oauth-2.0-flow.md) - Detailed token request guide
* [**Token Management**](/api/authentication/oauth-2.0-flow/best-practices-and-error-handling.md) - Best practices and error handling
* [**Request API Access**](/api/authentication/requesting-oauth-2.0-client.md) - How to get your credentials


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.partssource.com/api/authentication/overview.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
