Authentication
The Helthjem API uses Bearer JWT authentication with the OAuth 2.0 client credentials flow. You exchange your client_id and client_secret for an access token, and send that token with every request.
Get a token
Request
curl -X POST "https://api.pre.helthjem.no/auth/oauth2/v1/token" \
-H "Content-Type: application/json" \
-d '{
"client_id": "your-client-id",
"client_secret": "your-client-secret",
"grant_type": "client_credentials"
}'
Response
{
"token": "eyJhbGciOiJIUzI1Ni...",
"expires_in": 86400,
"token_type": "Bearer"
}
| Field | Description |
|---|---|
token |
The access token. |
expires_in |
How long the token is valid, in seconds. 86400 = 24 hours. |
token_type |
Always Bearer. |
If the credentials are wrong, the API responds with 401.
Use the token
Send these headers with every request to the API:
Authorization: Bearer <token>
Content-Type: application/json
Cache and refresh the token
Tokens are valid for 23 hours. Don't request a new token for every API call.
- Request a token and store it, together with the time it expires.
- Reuse the stored token for all requests.
- Request a new token shortly before the old one expires. Refreshing every 12 hours is a simple, safe option.
- If a request returns
401, request a new token and retry the request once.
If you run several servers or processes, share one cached token between them rather than having each one request its own.
Errors
| Status | errorKey |
Meaning | What to do |
|---|---|---|---|
401 |
authentication.failure / authentication.missing |
The token is missing, invalid or expired. | Request a new token and retry. |
403 |
no.access.shop.id |
Your credentials don't have access to the shopId in the request. |
Check that you're using the right shopId for the environment. |
403 |
no.access.api |
Your credentials don't have access to this API. | Contact integrations@helthjem.no. |
See Errors for the full error format.
Keep credentials secure
Your credentials carry many privileges. Keep the client_secret on your server and never expose it in client-side code, mobile apps or public repositories. If you think a secret has leaked, contact integrations@helthjem.no to have it replaced.
