For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Many integration platforms and GRC tools expect OAuth 2.0 rather than a static API key. An OAuth client gives them that: the platform holds a client ID and secret, asks Coverbase for a bearer token when it needs one, and uses the token until it expires, at most an hour later. The token reaches exactly what an ak_* key reaches. Endpoint details are in the OAuth API reference.
When to use it
Both authenticate as your organization’s API service account. The IP allowlist, the public API audit log and every route’s permissions apply the same way.
Step 1: Create the client
- Open Configuration and choose API keys.
- Under OAuth Clients, click New client.
- Give it a Name, such as “GRC sync”.
- Under Elevated Scopes, choose any scopes the integration needs. Most need none, which the list shows as Standard access. Only an admin signed in to the dashboard can grant scopes.
- Click Create client.
- Copy the Client ID and Client Secret, store the secret in your platform’s secret store, and click I saved the secret. The secret is not shown again.
POST /v1/api-oauth-clients with access_token_ttl_seconds.
Step 2: Configure your platform
In your integration platform’s OAuth 2.0 client credentials connection, enter:Step 3: Test it
cURL
{"msg": "Auth successful"} means the token works. Request a new token when expires_in runs out. This grant has no refresh token. Reuse a token until it expires: a client holds at most 50 live tokens, and requesting a 51st revokes its oldest.
Revoke
On the API keys page, click Revoke on the client and confirm Revoke client. The client can no longer get tokens, and its current tokens stop working. A server that cached a token can keep accepting it for a few seconds. Last Token shows when each client last asked for a token, which helps find clients nobody uses.Troubleshooting
Related
OAuth API
The token endpoint and client management.
API conventions
Authentication, scopes, errors and pagination.
Integration platforms
Workato, MuleSoft and Boomi.
Integration credentials and signing
How client secrets are stored.