Skip to main content

Create an auth profile

POST 

/v1/auth-profiles

Register an OAuth2 client credentials profile that the platform uses to authenticate to your webhook endpoint. Requires the connector:auth-profiles:create scope and an Idempotency-Key header. Creating a profile has no effect on deliveries until you bind it to a webhook with POST /v1/webhooks/{webhook_id}/bind.

How the platform uses the profile​

Before delivering to a webhook bound to this profile, the platform requests a token from token_endpoint_url:

POST /oauth2/token HTTP/1.1
Content-Type: application/x-www-form-urlencoded

grant_type=client_credentials&client_id=lyriq-webhook-sender&client_secret=...&scope=webhooks.receive

The client credentials are sent in the form body (client_secret_post). Your token endpoint must answer 2xx with a JSON body containing access_token and, optionally, expires_in in seconds (300 is assumed when absent). The platform caches the token per profile and requests a new one 30 seconds before it expires, or immediately after the profile is updated. The token is sent on each delivery as Authorization: Bearer <access_token>; the HMAC signature is sent as well.

If the token endpoint times out, cannot be reached, or answers 429 or 5xx, the delivery is retried later. Any other error status, or a body without access_token, fails the delivery permanently. The token endpoint must be an https:// URL that resolves to a public address.

Request and result​

All attributes are required. client_id, client_secret and requested_scope must not be empty; token_endpoint_url must be an absolute https:// URL with a host. profile_type must be OAuth2. The response is 202 Accepted; the new auth_profile_id is the relationships.resource.data.id of GET /v1/operations/{operation_id}. Retrying with the same Idempotency-Key and body returns the same 202 document without creating a second profile.

Request​

Responses​

Accepted. The operation (data.id) tracks the creation; read the new auth_profile_id from the operation's relationships.resource.