Authorization: Bearer <credential>. The
API tells them apart; the clients only attach the one you give them.
Credential types
Each endpoint in the API reference lists the credentials it
accepts, and a few endpoints need none. Use the narrowest credential that
reaches the endpoints you call: a project API key for work inside one project,
a service identity credential for automation in one organization, and an
account service key only when you need account-wide access.
Never send an M2M client secret to an API endpoint. Keep account service keys,
project API keys, and service identity credentials on your servers: do not embed
them in browser or mobile apps.
Pass a credential
In TypeScript and Python, pass the header in the client’sheaders option. In
Rust, register the credential under the security scheme it belongs to with
PhotonClientBuilder::credential.
Security schemes in Rust
The Rust client checks each operation’s accepted credentials before it sends anything. Register your credential under its scheme name from the table above:"accountServiceKey", "projectApiKey", "serviceIdentityBearer", or
"oauth2". If no registered credential matches an endpoint, the call fails with
Error::RequestConstruction and no request is sent. An Authorization header
set through static_headers or headers does not count as a registered
credential.
Project API keys
A project API key works only on endpoints under/v1/projects/{projectId}, for
the project it belongs to. In Rust, register it as "projectApiKey":
OAuth access tokens
The clients do not run OAuth flows: they do not open authorization pages, exchange codes, or refresh tokens. Your application’s own login flow obtains the access token and refreshes it. Give the client a function that returns the current token:- TypeScript:
headerscan be a function, sync or async. It is called before every attempt, including retries. - Python:
headerscan be a callable. It is called before every attempt, including retries. ForAsyncPhotonit can be async; forPhotonit must be synchronous. - Rust: register a
Credential::Providerunder"oauth2". It is called once each time you call an operation that uses it; the client’s retries of that call reuse the token.
oauth2 and only within the
scopes the user granted. Each endpoint in the API reference
lists the scope it needs.