Credentials consist of
- API Key : API Client identifier, can be shared.
- API Secret : Shared secret between client and Ifeelgoods.
These credentials are specific to each environment (as described above) and allow you to access your resources exclusively. To get your credentials, please reach out to your Ifeelgoods contact at [email protected].
Two authentication methods are possible :
- Header-based authentication (embedding Api-Key and Api-Secret in headers on every request) ⚠️DEPRECATED
- Token-based authentication (obtaining a temporary Bearer token via OAuth2 Client Credentials) RECOMMENDED
API Key-based Authentication
Deprecated
This authentication method is deprecated and will be removed in the future. Please migrate to OAuth2 token-based authentication.
A simple approach is to include the API credentials in the headers directly, using Api-Key and Api-Secret.
Api-Key: {IFEELGOODS_API_KEY}
Api-Secret: {IFEELGOODS_API_SECRET}Token-based Authentication (OAuth2)
We implement the standard OAuth 2.0 Client Credentials Grant (grant_type=client_credentials) for Server-to-Server (Machine-to-Machine) authentication.
This flow allows you to authenticate directly using your API credentials to receive a short-lived access token.
Environments & Endpoints
Depending on the environment you are targeting, you must use the appropriate base URL for the OAuth API. Notice that the production environment does not contain the -sandbox suffix:
- Sandbox:
https://oauth-sandbox.ifeelgoods.com/oauth/token - Production:
https://oauth.ifeelgoods.com/oauth/token
Token generation
Access tokens are issued by requesting the OAuth endpoint with your API credentials.
curl 'https://oauth-sandbox.ifeelgoods.com/oauth/token' \
--header 'Content-Type: application/json' \
--data '{
"client_id": IFEELGOODS_API_KEY,
"client_secret": IFEELGOODS_API_SECRET,
"grant_type": "client_credentials"
}'Example Response:
{
"access_token": "XXXX",
"token_type": "Bearer",
"expires_in": 1799,
"scope": "public",
"created_at": 1789738954
}
Important: You must cache your tokenYou must store and reuse your access token across your API requests. Do not request a new token for every single API call, as the token generation endpoint is subject to strict rate limits.
We strongly recommend reusing your cached token and requesting a new one only a few minutes (e.g., 5 minutes) before its validity period expires.
Using the token
Include the access token in all subsequent requests using the standard Authorization header:
"Authorization": "Bearer {IFEELGOODS_OAUTH_TOKEN}"Why Migrate to OAuth2?
Both methods are designed for Server-to-Server integrations, but OAuth2 provides enhanced security and flexibility:
- Reduced Secret Exposure: Your
API Secretis transmitted only once per token generation window, rather than on every single HTTP request. - Short-lived Credentials: Compromised bearer tokens automatically expire after a brief period, minimizing security risk compared to static keys.
- Standardization: Built on standard OAuth 2.0 specifications, allowing you to use standard OAuth client libraries in your framework.
Please contact us at [email protected] for more information.