OAuth and environments
ScanSource uses OAuth 2.0 client credentials for application access, plus a subscription key on the API gateway.
Send the access token as Authorization: Bearer {token}. Obtain tokens from the OAuth token URL for your environment using organization Client ID and Client Secret (client credentials grant).
Do not use a personal developer Try It key as the production identity.
Start here · Sign in · Account & sign-in help · Popular platforms
Warning: organization credentials vs Try It keys
Client ID and Client Secret are unique to your organization. After Active, open Profile → Organization Subscription Information for organization Client ID, Client Secret, and organization subscription key.
Portal Primary and Secondary subscription keys (shown with APIs / Try It) are for portal testing only — not for platforms or production.
Find Try It on API details after you pick an API and operation (also reachable from APIs). Prefer DEV/TEST for interactive calls — not as a production runtime.
How authentication works
Client credentials grant
Your application exchanges organization Client ID and Client Secret for an access token, then calls APIs with that token.
Subscription key
Required by the API gateway as Ocp-Apim-Subscription-Key. Production apps use the organization subscription key from Organization Subscription Information, not a personal Try it key.
Portal Try It
After Active, open APIs → an operation on API details → Try this operation. Use portal subscription keys for those interactive calls only. Prefer DEV/TEST (sandbox gateway) for day-to-day work — not PROD as normal practice.
Endpoints
Use sandbox (TEST) hosts for integration work. Use production hosts only with production app credentials. Do not mix environments.
Sandbox (TEST)
OAuth Server
https://login.microsoftonline.com/scansourceb2cqas.onmicrosoft.com/oauth2/v2.0/token
Scope
https://scansourceb2cqas.onmicrosoft.com/8e3cf5bd-9d8d-407d-b0ac-0fbe2a3dab68/.default
API Gateway
https://apitest.scansource.com
Partner portal
https://partnertestportal.scansource.com
Production
OAuth Server
https://login.microsoftonline.com/scansourceb2c.onmicrosoft.com/oauth2/v2.0/token
Scope
https://scansourceb2c.onmicrosoft.com/a2eccdbd-b208-4e77-a82f-dddd1814309a/.default
API Gateway
https://api.scansource.com/
Partner portal
https://partnerportal.scansource.com
Get a token (Sandbox example)
POST application/x-www-form-urlencoded to the OAuth Server with grant_type=client_credentials, your organization client_id and client_secret, and the sandbox scope. Replace the placeholders — never commit or email real secrets.
curl -X POST \-H "Content-Type: application/x-www-form-urlencoded" \-d "client_id={YOUR_CLIENT_ID}&scope=https://scansourceb2cqas.onmicrosoft.com/8e3cf5bd-9d8d-407d-b0ac-0fbe2a3dab68/.default&client_secret={YOUR_CLIENT_SECRET}&grant_type=client_credentials" \"https://login.microsoftonline.com/scansourceb2cqas.onmicrosoft.com/oauth2/v2.0/token"
Each token lasts 60 minutes. Renew before expiry, or request a new token when needed (including once per call if that fits your client).
Call an API
On each request to the API Gateway, send:
• Authorization: Bearer {access_token}
• Ocp-Apim-Subscription-Key: organization subscription key from Profile
Example: Pricing and availability against the sandbox API Gateway with both headers set. Specs and Try It for entitled products open after Active on API details (deep links from journeys land on the right operation).
Platform connectors vs custom APIs
Path A — platforms
Paste organization credentials into the vendor tool (for example QuoteWerks). You usually do not hand-build OAuth token requests.
Path B — Partner Direct
Your middleware obtains tokens with client credentials (see Endpoints and curl above) and calls entitled APIs. Specs and Try It open after approval on API details — prefer DEV/TEST.
Frequently asked questions
Can I use Try it keys in production?
No. Use organization Client ID, Client Secret, and organization subscription key from Profile → Organization Subscription Information after Active.
How do I get a token?
POST client credentials to the OAuth Server for your environment (sandbox or production) with the matching Scope listed under Endpoints. Use the sandbox curl sample above for TEST.
Why both token and subscription key?
The API Management gateway enforces Ocp-Apim-Subscription-Key in addition to the Bearer token for most products.
Platform connector — do I build OAuth?
You still need organization credentials after Active. OAuth token plumbing is usually inside the vendor connector.
Why can’t I see credentials or APIs?
Your account is not Active, or products are not assigned. Submitted means review is in progress.
Ready to continue?
Sign in · Start here · Account & sign-in help · Popular platforms