OAuth 2.0 client credentials
Snapdocs Connect eClose, Post Close QC, and eVault authenticate with the OAuth 2.0 client credentials grant. You exchange a client ID and secret for a bearer token, then send that token on every request. Notary Connect works differently; each has its own page.
Get your credentials
Your Customer Success Manager or Implementations Rep provides your client_id, client_secret, and the list of scopes your integration has access to. Credentials aren't available as a self-service download. The Snapdocs credential sharing will go direct to the party configuring the environment, and should be managed with your secrets policies in a secrets manager. Do not check these into your source control.
Request a token
POST to the /oauth/token endpoint of your environment's token host (hosts are in Environments and base URLs) with four parameters:
| Parameter | Value |
|---|---|
client_id | The Client ID provided by Snapdocs. |
client_secret | The Client Secret provided by Snapdocs. |
grant_type | Always client_credentials. |
audience | The API(s) the token is for, e.g. https://api.snapdocs.com in production or https://api.*.snpd.io in demo. |
from requests import Session token_url = "https://login.demo-eks.snpd.io/oauth/token" api_url = "https://api.cs-demo0.snpd.io/api/v1/subscriptions" data = { "client_id": "CLIENT_ID_HERE", "client_secret": "CLIENT_SECRET_HERE", "audience": "https://api.*.snpd.io", "grant_type": "client_credentials", } s = Session() token_response = s.post(token_url, data=data) token_response.raise_for_status() access_token = token_response.json()["access_token"] response = s.get(api_url, headers={"Authorization": "Bearer " + access_token}) response.raise_for_status() print(response.text)
The response includes access_token, token_type, and expires_in (seconds).
Cache the token and reuse it until it expires, then request a new one. Requesting a fresh token per API call adds latency and load for no benefit. Cache and reuse bearer tokens shows the pattern.
Use the token
Send the token on every request:
Authorization: Bearer {access_token}
A request with a missing, expired, or invalid token returns 401 Unauthorized. On a 401, invalidate your cached token, fetch a new one, and retry the request once.
You can inspect a JWT token for its scopes, audience, and expiry. You can use online tools including pasting it into jwt.io.
Scopes
Scopes are space-delimited authorization codes attached to your token, and they're product-specific. You should receive information about what scopes your credentials carry. The scope-to-endpoint mappings live with each product: eClose scopes, Post Close QC scopes in its reference, and eVault's in eVault's Authentication Overview.