Manage OAuth 2.0 Clients

OAuth2 · RFC 6749 · Client Credentials

OAuth2 Clients

Create and manage OAuth2 clients for API access. Each client is assigned individual scopes (permissions) and can generate tokens that are valid for 1 hour.

POST /oauth/token
grant_type=client_credentials

Client Credentials Flow

The OAuth2 Client Credentials Grant (RFC 6749 Section 4.4) for machine-to-machine authentication

1

Create a client

In the backend, under Tools → xoPort OAuth2 Clients, create a new client with the desired scopes.

2

Request a token

Use the client ID and secret to request an access token from the /oauth/token endpoint.

3

Use the API

Use the token in the ` Authorization: Bearer ` header for all API requests.

Request a token

curl -X POST https://shop.de/xpanel/xoport/oauth/token 
  -H "Content-Type: application/x-www-form-urlencoded" 
  -d "grant_type=client_credentials" 
  -d "client_id=xoc_abc123..." 
  -d "client_secret=xos_def456..."

Response

{
  "access_token": "xoat_eyJhbGciOiJIUzI1NiIs...",
  "token_type": "Bearer",
  "expires_in": 3600,
  "scope": "products:read products:write categories:read"
}

Available scopes

Scope Description Operations
products:read Read products GET
products:write Create/update products POST
products:delete Delete products DELETE
categories:read Read Categories GET
categories:write Create/update categories POST
categories:delete Delete Categories DELETE
customers:read Read customers GET
customers:write Create/update customers POST
customers:delete Delete customers DELETE
manufacturers:read Read manufacturers GET
manufacturers:write Create/update manufacturers POST
manufacturers:delete Delete manufacturers DELETE
orders:read Read Orders GET
news:read Read news articles GET
news:write Create/update news articles POST
news:delete Delete news article DELETE
newscategories:read Read news categories GET
newscategories:write Create/update news categories POST
newscategories:delete Delete news categories DELETE
faq:read Read FAQ GET
faq:write Create/Update FAQ POST
faq:delete Delete FAQ DELETE
faqcategories:read Read FAQ Categories GET
faqcategories:write Create/update FAQ categories POST
faqcategories:delete Delete FAQ Categories DELETE

Scope Introspection

You can use the /me endpoint to query the scopes of the current token:

curl -X GET https://shop.de/xpanel/xoport/me 
  -H "Authorization: Bearer xoat_eyJhbGciOi..."

Response

{
  "success": true,
  "client_id": "xoc_abc123...",
  "client_name": "Mein API Client",
  "scopes": ["products:read", "products:write", "categories:read"],
  "token_expires_at": "2026-01-26T20:00:00+01:00"
}

IP Restriction (optional)

Since v2.119.0, the REST API always requires an OAuth2 token, and its scopes apply. IP authorization for the XML interface (XML_PORT_IP_FILTER) does not grant access to the REST API.

Additionally, you can restrict access to specific IP addresses. If the setting XOPORT_REST_IP_LIST is populated, a request must originate from a listed IP address and include a valid token; the list never replaces the token. Requests from other IP addresses receive the response 403 with reason: deny_ip_not_listed.

Security Note

Never store the client secret or access token in front-end code or in public repositories!