Manage OAuth 2.0 Clients
OAuth2 Clients
Create and manage OAuth2 clients for API access. Each client is assigned individual scopes (permissions) and can generate tokens that are valid for 1 hour.
POST /oauth/token
grant_type=client_credentials
Client Credentials Flow
The OAuth2 Client Credentials Grant (RFC 6749 Section 4.4) for machine-to-machine authentication
Create a client
In the backend, under Tools → xoPort OAuth2 Clients, create a new client with the desired scopes.
Request a token
Use the client ID and secret to request an access token from the /oauth/token endpoint.
Use the API
Use the token in the ` Authorization: Bearer ` header for all API requests.
Request a token
curl -X POST https://shop.de/xpanel/xoport/oauth/token
-H "Content-Type: application/x-www-form-urlencoded"
-d "grant_type=client_credentials"
-d "client_id=xoc_abc123..."
-d "client_secret=xos_def456..."
Response
{
"access_token": "xoat_eyJhbGciOiJIUzI1NiIs...",
"token_type": "Bearer",
"expires_in": 3600,
"scope": "products:read products:write categories:read"
}
Available scopes
| Scope | Description | Operations |
|---|---|---|
products:read |
Read products | GET |
products:write |
Create/update products | POST |
products:delete |
Delete products | DELETE |
categories:read |
Read Categories | GET |
categories:write |
Create/update categories | POST |
categories:delete |
Delete Categories | DELETE |
customers:read |
Read customers | GET |
customers:write |
Create/update customers | POST |
customers:delete |
Delete customers | DELETE |
manufacturers:read |
Read manufacturers | GET |
manufacturers:write |
Create/update manufacturers | POST |
manufacturers:delete |
Delete manufacturers | DELETE |
orders:read |
Read Orders | GET |
news:read |
Read news articles | GET |
news:write |
Create/update news articles | POST |
news:delete |
Delete news article | DELETE |
newscategories:read |
Read news categories | GET |
newscategories:write |
Create/update news categories | POST |
newscategories:delete |
Delete news categories | DELETE |
faq:read |
Read FAQ | GET |
faq:write |
Create/Update FAQ | POST |
faq:delete |
Delete FAQ | DELETE |
faqcategories:read |
Read FAQ Categories | GET |
faqcategories:write |
Create/update FAQ categories | POST |
faqcategories:delete |
Delete FAQ Categories | DELETE |
Scope Introspection
You can use the /me endpoint to query the scopes of the current token:
curl -X GET https://shop.de/xpanel/xoport/me
-H "Authorization: Bearer xoat_eyJhbGciOi..."
Response
{
"success": true,
"client_id": "xoc_abc123...",
"client_name": "Mein API Client",
"scopes": ["products:read", "products:write", "categories:read"],
"token_expires_at": "2026-01-26T20:00:00+01:00"
}
IP Restriction (optional)
Since v2.119.0, the REST API always requires an OAuth2 token, and its scopes apply. IP authorization for the XML interface (XML_PORT_IP_FILTER) does not grant access to the REST API.
Additionally, you can restrict access to specific IP addresses. If the setting XOPORT_REST_IP_LIST is populated, a request must originate from a listed IP address and include a valid token; the list never replaces the token. Requests from other IP addresses receive the response 403 with reason: deny_ip_not_listed.
Security Note
Never store the client secret or access token in front-end code or in public repositories!