OAuth 2.0 client credentials

Snapdocs Connect eClose, Post Close QC, and eVault authenticate with the OAuth 2.0 client credentials grant. You exchange a client ID and secret for a bearer token, then send that token on every request. Notary Connect works differently; each has its own page.

Get your credentials

Your Customer Success Manager or Implementations Rep provides your client_id, client_secret, and the list of scopes your integration has access to. Credentials aren't available as a self-service download. The Snapdocs credential sharing will go direct to the party configuring the environment, and should be managed with your secrets policies in a secrets manager. Do not check these into your source control.

Request a token

POST to the /oauth/token endpoint of your environment's token host (hosts are in Environments and base URLs) with four parameters:

ParameterValue
client_idThe Client ID provided by Snapdocs.
client_secretThe Client Secret provided by Snapdocs.
grant_typeAlways client_credentials.
audienceThe API(s) the token is for, e.g. https://api.snapdocs.com in production or https://api.*.snpd.io in demo.
from requests import Session

token_url = "https://login.demo-eks.snpd.io/oauth/token"
api_url = "https://api.cs-demo0.snpd.io/api/v1/subscriptions"

data = {
    "client_id": "CLIENT_ID_HERE",
    "client_secret": "CLIENT_SECRET_HERE",
    "audience": "https://api.*.snpd.io",
    "grant_type": "client_credentials",
}

s = Session()
token_response = s.post(token_url, data=data)
token_response.raise_for_status()
access_token = token_response.json()["access_token"]

response = s.get(api_url, headers={"Authorization": "Bearer " + access_token})
response.raise_for_status()
print(response.text)

The response includes access_token, token_type, and expires_in (seconds).

🚧
Tokens expire after 2 hours, and there are no refresh tokens.

Cache the token and reuse it until it expires, then request a new one. Requesting a fresh token per API call adds latency and load for no benefit. Cache and reuse bearer tokens shows the pattern.

Use the token

Send the token on every request:

Authorization: Bearer {access_token}

A request with a missing, expired, or invalid token returns 401 Unauthorized. On a 401, invalidate your cached token, fetch a new one, and retry the request once.

You can inspect a JWT token for its scopes, audience, and expiry. You can use online tools including pasting it into jwt.io.

Scopes

Scopes are space-delimited authorization codes attached to your token, and they're product-specific. You should receive information about what scopes your credentials carry. The scope-to-endpoint mappings live with each product: eClose scopes, Post Close QC scopes in its reference, and eVault's in eVault's Authentication Overview.