Authentication Overview

Authentication

Snapdocs eVault uses OAuth 2.0, an industry-standard protocol that allows us to grant access to our API without sharing unique credentials with a third party. Tokens assigned to authenticated clients are required to access protected resources.

OAuth 2.0 Grant Type

The type of access called "OAuth 2.0 grant type" used for Snapdocs eVault is client credentials. Here, the username and password are not required, instead, you obtain the Access Token by providing the client id, client secret, and the audience.

Client ID, Client Secret, Grant, Scope and Audience

Your Customer Success Manager will reach out to you and provide your Client ID, Client Secret, as well as a list of scopes you have access to. These API keys carry many privileges, so be sure to keep them secure!

  • client_id the unique Client ID provided by Snapdocs
  • client_secret the unique Client Secret provided by Snapdocs
  • grant_type always set to client_credentials
  • audience the API you intend to call using the token generated by this request, example https://evault-user-login.snapdocs.com/api/federated_apps/
  • scope the authorization codes used to control the access to API endpoints, examples:
    • documents:basic used for eNote creation
    • auto_validation:basic used for auto validation

Access Token

The access token is obtained by doing a POST call to the Authorization Server's token endpoint

📘
A token expires 2 hours from issue time. We do not support refresh tokens at this time
🚧
To optimize system performance and ensure API stability, clients should cache and reuse authentication tokens for the entire duration of their validity. See the Auth Bearer Token Caching section for more information.

Access tokens are mapped to your credentials and determine your authorization to call the approved APIs you connected to your App.

Access protected resources

All requests you make to Snapdocs eVault must contain a valid access token. Requests with invalid tokens will be denied access to the resource with the API, returning an HTTP 401 status code.