# API Authentication

## Credentials

To interact with the Coactive API, you will need an access token. A short-lived access token (1 hour) can be generated via the `/login` endpoint (see below) with either a [personal token](#using-a-personal-token-recommended) or [system credentials](#using-system-credentials). You can find these values in the [settings](https://app.coactive.ai/settings/credentials) page.

#### Prerequisites

- All users can obtain a personal access token, which is subject to an expiration date of 30 days of no use or 3 months from its time of creation.
- System administrators can obtain system credentials that do not expire.

### Retrieving the Personal Token or System Credentials

#### Steps to retrieve credentials in the Coactive dashboard

#### Sign Into Your Organization

1. Go to the Coactive login page: [https://app.coactive.ai/](https://app.coactive.ai/).
2. Enter your org name and sign in using your account.

#### Navigate to Settings

1. Once logged in, locate your profile name in the **top right-hand corner** of the dashboard.
2. Click on your name to open a dropdown menu.
3. Select **Settings** from the dropdown options.

#### Access Credentials

1. In the Settings menu, look for the **Credentials** option on the **left-hand side** of the screen.
2. Click on **Credentials** to view your personal and system API credentials.

#### Retrieve Personal Token or System Credentials

1. On the Credentials page, you will find your Personal Token
   - `PERSONAL_TOKEN`: A unique token that represents your user access, can be regenerated. Once you generate this token, you must copy it and store it securely because Coactive does not store it.
2. On the Credentials page, you will find the following:
   - `CLIENT_ID`: A unique identifier for your organization.
   - `CLIENT_SECRET`: A secure key used to authenticate your organization.
3. Copy these values and store them securely.

---

## Creating an Access Token

#### Using a Personal Token (Recommended)

Exchange your `PERSONAL_TOKEN` for an access token using bearer token authentication.

```bash
curl --request POST 'https://api.coactive.ai/api/v0/login' \
  --header 'Authorization: Bearer <PERSONAL_TOKEN>' \
  --header 'Content-Type: application/json' \
  --data '{"grant_type": "refresh_token"}'
```

#### Using System Credentials

Exchange the `CLIENT_ID` and `CLIENT_SECRET` for an access token using basic authentication.

```bash
curl --request POST 'https://api.coactive.ai/api/v0/login' \
  -u '<CLIENT_ID>:<CLIENT_SECRET>' \
  --header 'Content-Type: application/json' \
  --data '{"grant_type": "client_credentials"}'
```

If successful, you will receive an `access_token` with an expiry of 1 hour (3600 seconds).

#### Example 200 Response

```json wordWrap
  {
      "access_token": "<ACCESS_TOKEN>",
      "token_type": "Bearer",
      "expires_in": 3600
  }
```

---

## Using the Access Token

With the retrieved `access_token`, you can authenicate to our APIs via Bearer Authentication.

```bash
Authorization: Bearer <ACCESS_TOKEN>
```

---

#### Important Notes

- `PERSONAL_TOKEN` has an expiry date and you cannot retrieve it post creation. You will be able to regenerate this personal token on the Coactive UI.
- Keep your `CLIENT_ID` and `CLIENT_SECRET` confidential. Do not share them publicly or commit them to version control systems.
- If you suspect your credentials have been compromised, please regenerate them through the dashboard or contact your Coactive representative to have them regenerated.

For further assistance, please contact Coactive support at [support@coactive.ai](mailto\:support@coactive.ai).