Auth
Authentication for partner and account users (login, OAuth password grant, impersonation), plus public pre-login reference lookups.
Authentication for partner and account users (login, OAuth password grant, impersonation), plus public pre-login reference lookups.
Terminology
These docs use one name per concept. Where the field name differs, it is given here.
| Term | What it means | Field name |
|---|---|---|
| Partner | The top-level tenant. Reaches every account and location beneath it. | partner_id |
| Account | A business within a partner. Owns locations, campaigns and reports. | account_id |
| Location | A single site with its own review-site connections and reviews. | store_id |
brand appears in some field names and status values as the older name for an account, and store as the older name for a location. They refer to the same records.
Prerequisites
- A bearer token in the
Authorizationheader. Any endpoint that needs no token says so on its own page. - The id of each record the call targets. Every endpoint page lists the ids it needs.
Errors
| Status | Meaning |
|---|---|
401 | The bearer token is missing, expired or invalid |
403 | The token is valid but the record sits outside your account |
422 | The request failed validation — the response names the fields |
500 | Unexpected server error |
Individual endpoints may return more; each page lists its own.
In this section
Exchange a user's email and password for an access token and a refresh token (password grant).
Admin-scoped OAuth client registration, plus the external JumpCloud OIDC SSO handoff.
Public reference catalogs (countries, states, cities, feature options) for pre-login forms.
Updated 15 days ago
