> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.talqora.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.talqora.com/_mcp/server.

# OAuth client credentials

Talqora supports OAuth 2.0 `client_credentials` for server-to-server and agent
retrieval. OAuth access tokens are short lived, carry only the `read` scope,
and are restricted to the indexes selected when the client was created.

## Create a client

Create a client from an authenticated workspace session with `POST
/v1/oauth/clients`. Save `client_secret` immediately: Talqora only returns it
when the client is created.

```json
{
  "name": "support-agent",
  "index_ids": ["idx_support"]
}
```

## Exchange credentials

Send the client ID and secret to the token endpoint using HTTP Basic
authentication or form fields. Request only `read`.

```bash
curl -X POST https://api.talqora.com/oauth/token \
  -u "$TALQORA_CLIENT_ID:$TALQORA_CLIENT_SECRET" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials&scope=read"
```

Use the returned bearer token only for retrieval in the granted indexes. It
expires in one hour. For vector writes, file processing, index administration,
or a long-lived integration, use an appropriately scoped Talqora API key and
idempotency key instead.

The authorization-server metadata is published at
`https://api.talqora.com/.well-known/oauth-authorization-server`.