For AI agents: a documentation index is available at the root level at /llms.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
Exchanges the `client_id` and `client_secret` for a Bearer access token (grant `client_credentials`, RFC 6749 §4.4). Both credentials are provided by Voices: request them from the Chat Bridge team. The `client_secret` is shown only once; when it is rotated, the previous one keeps working for 24 hours.
Send the token on every request as `Authorization: Bearer <access_token>`. It lasts 3600 seconds (`expires_in`); cache it and request a new one before it expires. Prefer the static API Key (`x-api-key`) instead? See the API Key page of this section.
Credentials can be sent in the body — as `application/json` or as `application/x-www-form-urlencoded` — or in an `Authorization: Basic base64(client_id:client_secret)` header. If both are present, the `Basic` header wins. The optional `scope` parameter is accepted and ignored: the token carries every permission of the App-Key.
Request
This endpoint expects an object.
grant_typeenumRequired
Must be client_credentials.
Allowed values:
client_idstringRequired<=64 characters
Client identifier of the App-Key (ck_ + 32 hex characters).
client_secretstringRequired<=128 characters
Client secret of the App-Key. Shown once when issued.
scopestringOptional
Accepted for compatibility and ignored.
Response
Token issued.
access_tokenstringOptional
JWT to send as Authorization: Bearer <access_token>.
token_typeenumOptional
Allowed values:
expires_inintegerOptional
Lifetime of the token in seconds (3600).
Errors
400
Bad Request Error
401
Unauthorized Error
429
Too Many Requests Error
Exchanges the client_id and client_secret for a Bearer access token (grant client_credentials, RFC 6749 §4.4). Both credentials are provided by Voices: request them from the Chat Bridge team. The client_secret is shown only once; when it is rotated, the previous one keeps working for 24 hours.
Send the token on every request as Authorization: Bearer <access_token>. It lasts 3600 seconds (expires_in); cache it and request a new one before it expires. Prefer the static API Key (x-api-key) instead? See the API Key page of this section.
Credentials can be sent in the body — as application/json or as application/x-www-form-urlencoded — or in an Authorization: Basic base64(client_id:client_secret) header. If both are present, the Basic header wins. The optional scope parameter is accepted and ignored: the token carries every permission of the App-Key.