> ## Documentation Index
> Fetch the complete documentation index at: https://docs.peerlogic.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Request a Peerlogic access token and use Bearer authentication for API requests.

Peerlogic API requests use Bearer access tokens. Request a token with your Peerlogic credentials, then include that token in the `Authorization` header on subsequent requests.

## Authentication flow

1. Request an access token from the token endpoint using your Peerlogic username and password.
2. Copy the `access_token` value from the response.
3. Include the token in the `Authorization` header for every secured API request.
4. Request a new token when the current token expires or the API returns `401 Unauthorized`.

<Note>
  Access to individual resources is determined by the permissions assigned to your Peerlogic account. A valid token can still receive `403 Forbidden` when the account does not have access to the requested resource.
</Note>

## Request a token

Send a form-encoded `POST` request to:

```text theme={null}
https://api.prod.peerlogic.com/api/oauth/token/
```

The request accepts the following values:

<ParamField body="username" type="string" required>
  Your Peerlogic username, usually your email address.
</ParamField>

<ParamField body="password" type="string" required>
  The password associated with your Peerlogic account.
</ParamField>

<ParamField body="grant_type" type="string" default="password">
  Use `password`.
</ParamField>

<ParamField body="format" type="string" default="json">
  Use `json`.
</ParamField>

```bash theme={null}
curl --request POST \
  --url https://api.prod.peerlogic.com/api/oauth/token/ \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'grant_type=password' \
  --data-urlencode 'format=json' \
  --data-urlencode 'username=<YOUR_USERNAME>' \
  --data-urlencode 'password=<YOUR_PASSWORD>'
```

## Token response

A successful response includes an access token, refresh token, expiration period, token type, and granted scope.

```json theme={null}
{
  "access_token": "<ACCESS_TOKEN>",
  "refresh_token": "<REFRESH_TOKEN>",
  "expires_in": 86400,
  "token_type": "Bearer",
  "scope": "offline_access"
}
```

## Authorize a request

Add the access token to the `Authorization` header. The word `Bearer` must precede the token, separated by a space:

```http theme={null}
Authorization: Bearer <ACCESS_TOKEN>
```

```bash theme={null}
curl --request GET \
  --url https://api.prod.peerlogic.com/api/calls/ \
  --header 'Authorization: Bearer <ACCESS_TOKEN>' \
  --header 'Accept: application/json'
```

When using **Try it** in this API reference, enter the access token in the Authorization field. Mintlify adds the Bearer authentication header to the request.

## Authentication errors

| Status | Meaning | What to do |
| - | - | - |
| `400 Bad Request` | The token request is missing a required value or contains an invalid value. | Verify the form fields and submit the request again. |
| `401 Unauthorized` | The credentials are invalid, the access token is missing, or the access token has expired. | Verify the credentials or request a new access token. |
| `403 Forbidden` | Authentication succeeded, but the account cannot access the requested resource. | Confirm that the account has access to the requested organization or practice. |

<Warning>
  Treat credentials, access tokens, and refresh tokens as secrets. Do not place them in browser code, logs, or source control.
</Warning>

## Next step

Use your token to [make your first API request](/quickstart). To determine which customer resources your account can use, see [Organization and practice access](/concepts/organizations-and-practices).


## Related topics

- [VoIP Platform authentication](/voip-platform/authentication.md)
- [Request an access token](/peerlogic-api-reference/authentication/request-an-access-token.md)
- [Make your first API request](/quickstart.md)
- [Organization, practice, and resource IDs](/concepts/organizations-and-practices.md)
- [List call filter options](/peerlogic-api-reference/call-insights/list-call-filter-options.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.