{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-authorizer-api/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"Authorizer API Overview"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"authorizer-api-overview","__idx":0},"children":["Authorizer API Overview"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"introduction","__idx":1},"children":["Introduction"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The EchoSync Authorizer is the authentication service for the EchoSync platform."," ","It validates your application credentials and issues ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Bearer tokens"]}," that grant"," ","access to EchoSync APIs. Every API request must include a valid Bearer token in"," ","its ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Authorization"]}," header."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"base-url","__idx":2},"children":["Base URL"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Production:"]}," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://auth.echo.com"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"authentication","__idx":3},"children":["Authentication"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["EchoSync Authorizer uses a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["token-based authentication"]}," flow. Submit your"," ","application credentials to receive a Bearer token, which must be included in"," ","every downstream API request."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"token-lifecycle","__idx":4},"children":["Token Lifecycle"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Reuse your token until it expires."]}," Do not request a new token on every API call. Cache the token and use it for its full validity period. Requesting new tokens repeatedly within the same validity window may trigger rate limiting."]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Access tokens are valid for ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["86400 seconds"]}," (24 hours) from the time they are issued."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The endpoint ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/token"]}," response includes:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["expires_in"]}," — token lifetime in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["seconds"]}," (used to determine when the token should be refreshed)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["scope"]}," — the permissions granted to the token, defining which APIs it can access"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401 Unauthorized"]}," response from any EchoSync API indicates the token is expired or invalid. In this case, request a new token and retry the request."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"rate-limiting","__idx":5},"children":["Rate Limiting"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To ensure fair usage, maintain service availability, and protect system performance, requests may be subject to rate limiting. When usage exceeds allowed thresholds, requests can be temporarily throttled or rejected until the limit window resets."]}]},"headings":[{"value":"Authorizer API Overview","id":"authorizer-api-overview","depth":1},{"value":"Introduction","id":"introduction","depth":2},{"value":"Base URL","id":"base-url","depth":2},{"value":"Authentication","id":"authentication","depth":2},{"value":"Token Lifecycle","id":"token-lifecycle","depth":2},{"value":"Rate Limiting","id":"rate-limiting","depth":2}],"frontmatter":{"id":"introduction","title":"Authorizer API Introduction","seo":{"title":"Authorizer API Overview"}},"lastModified":"2026-06-23T21:43:32.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/authorizer-api/introduction","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}