Authentication
You create a client with the client ID and client secret of an OAuth client. The library does the rest. It never asks you for an access token.
What the library does for you
- One exchange, shared. The first call that needs a token exchanges your credentials for one. If several calls start at once, they all wait on that one exchange rather than each starting their own.
- Cached until it is nearly stale. The token is reused until 60 seconds before it expires, then replaced on the next call. Nothing refreshes in the background, so an idle process makes no requests.
- One retry on 401. If the API rejects a token, the library forgets it, fetches a fresh one and repeats the call once. A second 401 is raised as an API error.
- A bounded exchange. A token request that gets no answer fails after 30 seconds, so a slow token endpoint cannot hold every caller.
- Nothing to leak. The client secret and every access token are printed as
[REDACTED]in logs, debug output and error messages.
Operations that need no token, such as listing API versions, never send one, so a client created without credentials can still call them.
Keep the secret on your server
A client secret identifies your application, not your users. Keep it in your server’s configuration or secret store, and never ship it to a browser or a mobile app.