> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://developer.artlist.io/authentication/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.artlist.io/_mcp/server. # Authentication > API Authentication > **Info** > > Artlist uses API keys to authenticate requests. \ > Currently, API keys are issued and managed through your account manager, but a self-service developer portal will be available soon. # OAuth 2.0 Authentication Artlist API uses the OAuth 2.0 Client Credentials flow for secure server-to-server authentication. # Overview The Client Credentials flow enables clients to authenticate directly with their client credentials, without requiring user interaction. # Credentials `client_id`: The unique client identifier provided by your account manager. \ `client_secret`: The secret key provided by your account manager keep this secure! # Getting an Access Token Token Endpoint ```mdx https://artlist-business-api-prod-cognito.artlist.io/oauth2/token ``` Request Headers ```mdx Content-Type: application/x-www-form-urlencoded Authorization: Basic token ``` # Before you make a request Youll need to encode the combination of your client\_id and client\_secret using Base64 in the following format: ```mdx “client_id”:”client_secret” → Base64 encoded ``` For example: ```mdx client_id: 1234 client_secret: abcd token = 1234:abcd → Base64 = MTIzNDphYmNkCg== So the header would be Authorization: Basic MTIzNDphYmNkCg== ``` # Request Body Example ```mdx 'grant_type=client_credentials' ``` Sample Response ```js { "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6...", "token_type": "Bearer", "expires_in": 3600 } ``` # Using the Token Add the token to your API requests: ```mdx Authorization: Bearer YOUR_ACCESS_TOKEN ``` # Security Considerations * Never expose your client\_secret in client-side code * Store client credentials securely * Rotate client credentials periodically * Access tokens expire after 1 hour, so make sure to regenerate them before theyit expire > API Authentication