Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Many integration platforms and GRC tools expect OAuth 2.0 rather than a static API key. An OAuth client gives them that: the platform holds a client ID and secret, asks Coverbase for a bearer token when it needs one, and uses the token until it expires, at most an hour later. The token reaches exactly what an ak_* key reaches. Endpoint details are in the OAuth API reference.

When to use it

Both authenticate as your organization’s API service account. The IP allowlist, the public API audit log and every route’s permissions apply the same way.

Step 1: Create the client

  1. Open Configuration and choose API keys.
  2. Under OAuth Clients, click New client.
  3. Give it a Name, such as “GRC sync”.
  4. Under Elevated Scopes, choose any scopes the integration needs. Most need none, which the list shows as Standard access. Only an admin signed in to the dashboard can grant scopes.
  5. Click Create client.
  6. Copy the Client ID and Client Secret, store the secret in your platform’s secret store, and click I saved the secret. The secret is not shown again.
Tokens from a client made on this page last one hour. To create a client with a shorter token lifetime, from five minutes up, use POST /v1/api-oauth-clients with access_token_ttl_seconds.

Step 2: Configure your platform

In your integration platform’s OAuth 2.0 client credentials connection, enter:

Step 3: Test it

cURL
{"msg": "Auth successful"} means the token works. Request a new token when expires_in runs out. This grant has no refresh token. Reuse a token until it expires: a client holds at most 50 live tokens, and requesting a 51st revokes its oldest.

Revoke

On the API keys page, click Revoke on the client and confirm Revoke client. The client can no longer get tokens, and its current tokens stop working. A server that cached a token can keep accepting it for a few seconds. Last Token shows when each client last asked for a token, which helps find clients nobody uses.

Troubleshooting

OAuth API

The token endpoint and client management.

API conventions

Authentication, scopes, errors and pagination.

Integration platforms

Workato, MuleSoft and Boomi.

Integration credentials and signing

How client secrets are stored.