Skip to main content

Authentication

TST Connect supports authentication via the OAuth client credentials flow.

1. Exchange your credentials for a token​

curl -s -u "$CLIENT_ID:$CLIENT_SECRET" \
-d grant_type=client_credentials \
https://tst-connect-dev.auth.us-east-1.amazoncognito.com/oauth2/token
{
"access_token": "<jwt>",
"expires_in": 3600,
"token_type": "Bearer"
}

2. Call the API with the token​

curl https://connect-dev.tstllc.net/shop/v1/cruise \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{"licensee": "..."}'

Token lifetime​

Tokens last one hour (expires_in, in seconds). There is no refresh token for this grant type — request a new one when the old expires.

Reuse a token until it expires rather than fetching one per request. The gateway caches authorization decisions per token for five minutes, so a fresh token on every call is both slower and wasteful.

Scopes​

Your client is provisioned with scopes named connect/<capability>, where the capability is the first path segment of the route — shop routes require connect/shop. You do not need to request scopes explicitly: omit the scope parameter and the token carries whatever your client is entitled to.

Trying it from these docs​

The API reference can do the exchange for you. Open Authorize on any operation, choose the scheme for the environment you are calling — connectOAuthDev or connectOAuthProd, which differ only in their token endpoint — paste your client ID and secret, and the reference fetches a token and attaches it to the requests you send from the page.

When something is rejected​

  • 401 — no token, or one that is invalid or expired. Request a new token and retry.
  • 403 — the token is valid, but your client is not entitled to that route. Check the route's capability against the scopes you were issued, and contact TST if it should be included.
  • 400 — the request itself failed validation. See the error body; this is unrelated to authentication.

If the token endpoint returns invalid_client, the client ID or secret is wrong, or the credentials were sent to the wrong pool.