Authentication

The Helthjem API uses Bearer JWT authentication with the OAuth 2.0 client credentials flow. You exchange your client_id and client_secret for an access token, and send that token with every request.

Get a token

Request

curl -X POST "https://api.pre.helthjem.no/auth/oauth2/v1/token" \
  -H "Content-Type: application/json" \
  -d '{
    "client_id": "your-client-id",
    "client_secret": "your-client-secret",
    "grant_type": "client_credentials"
  }'

Response

{
  "token": "eyJhbGciOiJIUzI1Ni...",
  "expires_in": 86400,
  "token_type": "Bearer"
}
Field Description
token The access token.
expires_in How long the token is valid, in seconds. 86400 = 24 hours.
token_type Always Bearer.

If the credentials are wrong, the API responds with 401.

Use the token

Send these headers with every request to the API:

Authorization: Bearer <token>
Content-Type: application/json

Cache and refresh the token

Tokens are valid for 23 hours. Don't request a new token for every API call.

  1. Request a token and store it, together with the time it expires.
  2. Reuse the stored token for all requests.
  3. Request a new token shortly before the old one expires. Refreshing every 12 hours is a simple, safe option.
  4. If a request returns 401, request a new token and retry the request once.

If you run several servers or processes, share one cached token between them rather than having each one request its own.

Errors

Status errorKey Meaning What to do
401 authentication.failure / authentication.missing The token is missing, invalid or expired. Request a new token and retry.
403 no.access.shop.id Your credentials don't have access to the shopId in the request. Check that you're using the right shopId for the environment.
403 no.access.api Your credentials don't have access to this API. Contact integrations@helthjem.no.

See Errors for the full error format.

Keep credentials secure

Your credentials carry many privileges. Keep the client_secret on your server and never expose it in client-side code, mobile apps or public repositories. If you think a secret has leaked, contact integrations@helthjem.no to have it replaced.

Last updated