Skip to navigation

OAuth client credentials

Talqora supports OAuth 2.0 client_credentials for server-to-server and agent retrieval. OAuth access tokens are short lived, carry only the read scope, and are restricted to the indexes selected when the client was created.

Create a client

Create a client from an authenticated workspace session with POST /v1/oauth/clients. Save client_secret immediately: Talqora only returns it when the client is created.

{
"name": "support-agent",
"index_ids": ["idx_support"]
}

Exchange credentials

Send the client ID and secret to the token endpoint using HTTP Basic authentication or form fields. Request only read.

curl -X POST https://api.talqora.com/oauth/token \
-u "$TALQORA_CLIENT_ID:$TALQORA_CLIENT_SECRET" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials&scope=read"

Use the returned bearer token only for retrieval in the granted indexes. It expires in one hour. For vector writes, file processing, index administration, or a long-lived integration, use an appropriately scoped Talqora API key and idempotency key instead.

The authorization-server metadata is published at https://api.talqora.com/.well-known/oauth-authorization-server.