REST API authentication in Allocadia (bearer token, 20-minute timeout)

Acquire a token via POST /token, use it as a Bearer header. Tokens expire after 20 minutes of inactivity.


Acquire a token

POST https://api-na.allocadia.com/v1/token
Content-Type: application/json

{
  "username": "customer.integrations@example.com",
  "password": "<password>"
}

The response contains the access token. Store it in memory for the lifetime of the integration's current operation.

Use the token on subsequent requests

Attach the token to every subsequent request in the Authorization header:

Authorization: Bearer 45f83356-14e7-4c81-8458-0b38c0a721b1

Both Bearer and token are accepted schemes — Bearer is recommended.

Token expiration

Tokens expire after 20 minutes of inactivity. Each authenticated call resets the timeout, so a continuously-running integration doesn't typically see expirations. Idle integrations should either:

  • Reacquire a token before each operation, or
  • Check for 401 Unauthorized on each request and refresh on failure.

Required user attributes

The user whose credentials you're using must have:

  • API access enabled on their user record (ask an admin to set this).
  • A local password set. SSO-only users don't have a local password and can't authenticate.

See Does my SSO user need a separate password to use the Allocadia API? for the full pattern on using a dedicated integration user.

Security notes

  • Store credentials securely on the integration side — never commit them to version control.
  • Use a dedicated integration user, not a human user's credentials.
  • Rotate the password periodically per your security policy. Allocadia supports password changes without disrupting token behavior — new tokens require the new password.

Related articles

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.