Skip to main content
Every Photon credential is sent as Authorization: Bearer <credential>. The API tells them apart; the clients only attach the one you give them.

Credential types

Each endpoint in the API reference lists the credentials it accepts, and a few endpoints need none. Use the narrowest credential that reaches the endpoints you call: a project API key for work inside one project, a service identity credential for automation in one organization, and an account service key only when you need account-wide access. Never send an M2M client secret to an API endpoint. Keep account service keys, project API keys, and service identity credentials on your servers: do not embed them in browser or mobile apps.

Pass a credential

In TypeScript and Python, pass the header in the client’s headers option. In Rust, register the credential under the security scheme it belongs to with PhotonClientBuilder::credential.

Security schemes in Rust

The Rust client checks each operation’s accepted credentials before it sends anything. Register your credential under its scheme name from the table above: "accountServiceKey", "projectApiKey", "serviceIdentityBearer", or "oauth2". If no registered credential matches an endpoint, the call fails with Error::RequestConstruction and no request is sent. An Authorization header set through static_headers or headers does not count as a registered credential.

Project API keys

A project API key works only on endpoints under /v1/projects/{projectId}, for the project it belongs to. In Rust, register it as "projectApiKey":

OAuth access tokens

The clients do not run OAuth flows: they do not open authorization pages, exchange codes, or refresh tokens. Your application’s own login flow obtains the access token and refreshes it. Give the client a function that returns the current token:
  • TypeScript: headers can be a function, sync or async. It is called before every attempt, including retries.
  • Python: headers can be a callable. It is called before every attempt, including retries. For AsyncPhoton it can be async; for Photon it must be synchronous.
  • Rust: register a Credential::Provider under "oauth2". It is called once each time you call an operation that uses it; the client’s retries of that call reuse the token.
An OAuth token works only on endpoints that accept oauth2 and only within the scopes the user granted. Each endpoint in the API reference lists the scope it needs.