Skip to content

Use the client credentials flow

Client credentials authentication for server apps

Section titled “Client credentials authentication for server apps”

The OAuth 2.0 client credentials flow is for machine-to-machine sign-in. It’s built for backend services and third-party apps. They call the Tallyfy API with no user logging in.

You’ll need a Client ID and Client Secret from Tallyfy Support before you start.

How the flow worksYour ApplicationTallyfy SupportTallyfy Auth(go.tallyfy.com)Tallyfy API(go.tallyfy.com/api) 1. Request clientcredentials2. Provide Client ID& Client Secret3. POST /oauth/token(client_credentials)4. Access token(expires in 7 days)5. API Request withBearer token + headers6. Response data7. POST /applications/users(provision user)8. User-specific token9. GET /organizations/tasks(as user)10. User's tasks data11. POST /oauth/token(re-request before expiry)12. New access token
  • Step 1 is manual. You contact Tallyfy Support for credentials once. You can’t automate it.
  • There are two token types. Application tokens are for system operations. User-specific tokens act as a particular user.
  • They last for different lengths of time. Application tokens expire in 7 days (604,800 seconds). User-specific tokens expire in 3 months (7,776,000 seconds).

This pattern works well when you want to:

  • Put Tallyfy features inside your own software.
  • Automate process management or user provisioning.
  • Build system-level integrations, such as reporting or data sync.
  • Give your users workflow features without separate Tallyfy logins.

Contact Tallyfy Support and describe your integration. They’ll give you a Client ID and Client Secret for your organization. Keep them somewhere safe.

First, your app needs its own access token. It uses this token for jobs like creating users or getting user-specific tokens.

  • Endpoint: POST https://go.tallyfy.com/oauth/token
  • Content-Type: application/x-www-form-urlencoded
  • Parameters:
    • grant_type: client_credentials
    • client_id: Your Client ID
    • client_secret: Your Client Secret
    • scope: * (optional)
const clientId = 'YOUR_CLIENT_ID';
const clientSecret = 'YOUR_CLIENT_SECRET';
const tokenUrl = 'https://go.tallyfy.com/oauth/token';
const params = new URLSearchParams();
params.append('grant_type', 'client_credentials');
params.append('client_id', clientId);
params.append('client_secret', clientSecret);
params.append('scope', '*');
const response = await fetch(tokenUrl, {
method: 'POST',
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
body: params
});
if (!response.ok) {
throw new Error(`HTTP error! status: ${response.status}`);
}
const data = await response.json();
console.log('Access token:', data.access_token);
// Use data.access_token for subsequent API calls

Response:

{
"token_type": "Bearer",
"expires_in": 604800,
"access_token": "eyJ0eXAiOiJKV1Q..."
}

With your application token, you can create users in your organization:

  • Endpoint: POST https://go.tallyfy.com/api/applications/{orgID}/users
  • Headers:
    • Authorization: Bearer {your_app_access_token}
    • Content-Type: application/json
    • X-Tallyfy-Client: APIClient
  • Body fields:
    • first_name (required): Max 32 characters
    • last_name (required): Max 32 characters
    • email (required): Must be unique, valid domain
    • role (optional): admin, standard, or light
    • timezone (optional): User’s timezone string

To act as a specific user, use your application token to get a user-scoped token.

  • Endpoint: POST https://go.tallyfy.com/api/applications/{orgID}/users/{email}/token
  • Headers:
    • Authorization: Bearer {your_app_access_token}
    • X-Tallyfy-Client: APIClient
  • Note: No request body needed - the user’s email goes in the URL path.

Response:

{
"token_type": "Bearer",
"expires_in": 7776000,
"access_token": "eyJ0eXAiOiJKV1Q..."
}

Use either token (application-level or user-specific) in your API calls. Send these required headers:

  • Authorization: Bearer {token}
  • Accept: application/json
  • X-Tallyfy-Client: APIClient

All API endpoints follow the pattern https://go.tallyfy.com/api/organizations/{orgID}/....

For code examples of specific API calls, see the personal access token guide. The requests look the same. Just swap in your token.

  • Keep client credentials in an encrypted secrets manager, never in source code.
  • Protect both application-level and user-specific tokens.
  • Rotate your secrets regularly.
  • Use HTTPS for all requests.
  • Get a new application token before the 7-day expiry.

Integrations > Open API

Tallyfy’s REST API gives developers full programmatic access to the same platform features that…