Acquire a token via POST /token, use it as a Bearer header. Tokens expire after 20 minutes of inactivity.
Acquire a token
POST https://api-na.allocadia.com/v1/token
Content-Type: application/json
{
"username": "customer.integrations@example.com",
"password": "<password>"
}
The response contains the access token. Store it in memory for the lifetime of the integration's current operation.
Use the token on subsequent requests
Attach the token to every subsequent request in the Authorization header:
Authorization: Bearer 45f83356-14e7-4c81-8458-0b38c0a721b1
Both Bearer and token are accepted schemes — Bearer is recommended.
Token expiration
Tokens expire after 20 minutes of inactivity. Each authenticated call resets the timeout, so a continuously-running integration doesn't typically see expirations. Idle integrations should either:
- Reacquire a token before each operation, or
- Check for 401 Unauthorized on each request and refresh on failure.
Required user attributes
The user whose credentials you're using must have:
- API access enabled on their user record (ask an admin to set this).
- A local password set. SSO-only users don't have a local password and can't authenticate.
See Does my SSO user need a separate password to use the Allocadia API? for the full pattern on using a dedicated integration user.
Security notes
- Store credentials securely on the integration side — never commit them to version control.
- Use a dedicated integration user, not a human user's credentials.
- Rotate the password periodically per your security policy. Allocadia supports password changes without disrupting token behavior — new tokens require the new password.
Comments
Please sign in to leave a comment.