Skip to content

Exchange API key for an access token

POST
/v1/auth/token
curl --request POST \
--url https://dev-api.infiniteaudience.ai/v1/auth/token \
--header 'Content-Type: application/json' \
--data '{ "api_key": "example" }'

Public endpoint — no token required. Exchanges an org API key (cf_live_...) for a short-lived Bearer access token. Include the returned access_token as Authorization: Bearer <access_token> on all subsequent protected requests. Suspended organisations and children of a suspended agency cannot exchange API keys.

Media typeapplication/json
object
api_key
required

Organisation API key in format cf_live_…

string
Examplegenerated
{
"api_key": "example"
}

Access token issued

Media typeapplication/json
object
access_token
required

Bearer access token — include as Authorization header on protected requests

string
token_type
required
string
expires_in
required

Token lifetime in seconds

integer
Example
{
"token_type": "bearer"
}

Invalid request — malformed body, missing required attribute, or failed validation. See error and message for details.

Media typeapplication/json
object
error
required

Stable machine-readable error code (e.g. INVALID_STATUS_TRANSITION, BILLING_INSUFFICIENT_BALANCE). Always present.

string
message

Human-readable explanation of the error.

string
code

Alternate machine-readable code — present on some endpoints as an alias for error for backward compatibility.

string
request_id

Opaque support/debug identifier when available.

string
key
additional properties
any
Examples
Examplevalidation_error
{
"error": "Bad Request",
"code": "MISSING_SEGMENTS",
"message": "segment_ids is required for filter audiences."
}

Missing or invalid Bearer token. Obtain one via POST /v1/auth/token. When a token was supplied but rejected, code distinguishes TOKEN_EXPIRED (the token’s lifetime has passed — request a new one via POST /v1/auth/token and retry) from TOKEN_INVALID (malformed or revoked — re-authenticate).

Media typeapplication/json
object
error
required

Stable machine-readable error code (e.g. INVALID_STATUS_TRANSITION, BILLING_INSUFFICIENT_BALANCE). Always present.

string
message

Human-readable explanation of the error.

string
code

Alternate machine-readable code — present on some endpoints as an alias for error for backward compatibility.

string
request_id

Opaque support/debug identifier when available.

string
key
additional properties
any
Examples
{
"error": "Unauthorized: Missing or invalid Authorization header"
}

The authenticated organisation is suspended or otherwise forbidden from performing this operation.

Media typeapplication/json
object
error
required

Stable machine-readable error code (e.g. INVALID_STATUS_TRANSITION, BILLING_INSUFFICIENT_BALANCE). Always present.

string
message

Human-readable explanation of the error.

string
code

Alternate machine-readable code — present on some endpoints as an alias for error for backward compatibility.

string
request_id

Opaque support/debug identifier when available.

string
key
additional properties
any
Examplegenerated
{
"error": "example",
"message": "example",
"code": "example",
"request_id": "example"
}