Skip to navigation

Application logic

Understand the application logic behind the Profile API.

Request authentication flow

The Profile API uses a standard OAuth flow:

1

Obtain credentials

Get your client_id and client_secret from the BCD engineering team.

2

Request an access token

POST to the /v3/oauth/token endpoint with your credentials to receive a bearer token.

3

Make API requests

Include the bearer token in the Authorization header of every API request.

4

Handle token expiration

Access tokens expire after 1 hour. Use the refresh token or request a new access token when the current one expires.