How authentication works
Snapdocs APIs leverage client_credentials OAuth2 flow for authentication. There are some key and Auth URL, and scope differences per product to watch out for. OAuth 2.0 client credentials covers the shared flow in detail, Cache and reuse bearer tokens covers token lifecycle, and below we link to each products specific page.
OAuth 2.0 client credentials
eClose, Post Close QC, and eVault all authenticate the same way:
- Snapdocs provisions a
client_idandclient_secretfor your integration. - You POST to the
/oauth/tokenendpoint withgrant_type=client_credentialsand theaudienceof the API you're calling. - You send the returned bearer token in the
Authorizationheader. Tokens expire after 2 hours, so cache and reuse them until expiration.
The above products differ only in audience and scopes:
| Product | Token host (production) | What differs |
|---|---|---|
| eClose | login.snapdocs.com | eClose scopes (see eClose scopes) |
| Post Close QC | login.snapdocs.com | QC scopes, same token endpoint |
| eVault | login.snapdocs.com | its own audience and scopes, see eVault's Authentication Overview |
The token endpoints are in the API Reference tab of this section, and hosts per environment are in Environments and base URLs.
Notary Connect Authentication
| Product | How it differs |
|---|---|
| Notary Connect | API Key Authentication, a static API key in the X-AUTH-TOKEN header, scoped to your company or client. See Notary Connect: Getting Started. |