> For the complete documentation index, see [llms.txt](https://doc.wearepatchworks.com/product-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.wearepatchworks.com/product-documentation/patchworks-services/inbound-api/using-the-inbound-api-connector-with-patchworks-services/generating-token-credentials-for-api-access.md).

# Generating token credentials for API access

## Introduction  <a href="#introduction" id="introduction"></a>

A Patchworks **access token** is required to authorise API requests for sending data to the inbound URL for a Patchworks service.

To obtain this token, you send a set of **client credentials** to a Patchworks **token endpoint**. Patchworks validates these credentials and returns an **access token** you can use to POST custom payload data to the required service. Once the custom payload is received, it’s processed in the usual way.These steps are illustrated below:

<figure><img src="https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLYNcUBVQwSkOMG6KjZfz%2Fuploads%2FTkjSiDy60CFDPwxVw0go%2Faccess%20token%20flow%203.png?alt=media&#x26;token=2e9a6b17-83d2-415d-9f61-369ce1ead677" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Access tokens are valid for 24 hours - for example: Issued: Wednesday 20th July at 10:03:08 GMT Expires: Tuesday 21st July at 10:03:08 GMT.
{% endhint %}

Use the **authentication** tab for an **Inbound API connector** to obtain/generate details required to request access tokens for secure access to the inbound URL for a Patchworks service. You will need:

* A Patchworks token endpoint
* OAuth credentials for this endpoint

{% hint style="info" %}
Patchworks uses **OAuth 2.0**. Watch this space for **Basic Authentication** support, coming soon!
{% endhint %}

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

To complete the steps detailed here, you must have completed the following tasks:

* [​Adding an Inbound API connector with a custom payload](/product-documentation/patchworks-services/inbound-api/using-the-inbound-api-connector-with-patchworks-services.md)

## The steps

Follow the steps below:

**Step 1**\
Select the **authentication** tab for the required **Inbound API Connector**:

![](/files/UZwMoWMriX6MTrGTZ51o)

<mark style="color:green;">These steps assume you are following a 'create new' connector flow. If you need to use an existing connector, find the required connector and select the</mark> <mark style="color:green;"></mark><mark style="color:green;">**authentication**</mark> <mark style="color:green;"></mark><mark style="color:green;">tab:</mark>

![](/files/o3eOKNV4whmma14IxEyJ)

**Step 2**\
Copy the **token endpoint** and paste it somewhere safe for future use:

![](/files/VsKbVbsOSqlQk1fqG9RD)

… when prompted, enter a name for this set of credentials:

![](/files/PnkldknYRq8B51ZfTmq1)

**Step 3**\
Move down to the **OAuth2 Clients** section and select **create an OAuth2 client**:

![](/files/VsKbVbsOSqlQk1fqG9RD)

… when prompted, enter a name for this set of credentials:

![](/files/PnkldknYRq8B51ZfTmq1)

**Step 4**\
Click the **create new OAuth2 client** button to confirm and display generated credentials:

![](/files/JHYEFR5F8gqNbsRY20kF)

**Step 5**\
Copy/paste this information somewhere safe for future use.

{% hint style="danger" %}
Once this page is closed, you can’t reaccess the client secret. If you lose this information, you need to generate a new set of credentials.
{% endhint %}

**Step 6**\
Click the **close** button to exit back to the connector **authentication** tab, where the new set of credentials is listed:

![](/files/NZM7Mu26lpuz3su6MK0e)

**Step 7**\
You are now ready to add a Patchworks service - see [Adding a Patchworks service for an Inbound API connector](/product-documentation/patchworks-services/inbound-api/using-the-inbound-api-connector-with-patchworks-services/adding-a-patchworks-service-for-an-inbound-api-connector.md).​
