Service clients
Route: /administration (Service clients) · Role: admin
A service client is a machine identity for server-to-server calls. It exchanges its client id and secret for a short-lived access token using the OpenAPI-compatible client-credentials grant.
Create a client
-
Open Administration → Service clients.
-
Fill in:
Field Notes Display name Human label, e.g. Accounting sync. client-id Lowercase letters, digits, and dashes (3–64 chars). Role engineer,reviewer,finance, oradmin.scopes Comma-separated; see below. -
Click Create client.
-
Copy the secret now — it is shown once.
Get an access token
curl -s -X POST https://intranet.example/api/v1/auth/token \
-H 'content-type: application/json' \
-d '{"grant_type":"client_credentials","client_id":"accounting-sync","client_secret":"..."}'
The response contains a short-lived opaque access token carrying the client's
role and scopes. Send it as Authorization: Bearer <token>.
Scopes
The same scope vocabulary as personal tokens:
customers:read projects:read time:read time:review
agreements:read billing:read billing:write reports:read admin:read
A read-only accounting integration typically needs billing:read and
reports:read.
Delete a client
Click Delete on the row. The client and its ability to exchange credentials are removed; existing issued tokens expire on their own.
To rotate a secret, delete and recreate the client, or issue a second client for the cutover window.
Rules
- Secrets are scrypt-hashed; only the hash is stored.
- The client's role is enforced exactly like a user's.
- Issued tokens are short-lived by design — fetch a new one per call window.