POST /credentials
Each resource gets a default pair of credentials (server-token type with global scope) when they are created (either by connecting with Google or as a plain resource). These give full access to the resource and if you're using API from your backend, you'll probably don't need to create more credentials.
Booking.js widget
If you want to use the booking.js widget, which runs in the browser, you'll need an API token that only provides access to some of the endpoints. This ensures that visitors cannot impersonate the user/resource and make illegal changes to resource data and see personal information. The widget only needs access to 3 endpoints:
To create these credentials, please set the following parameters:
- type: "client-token"
- scopes: "widget"
Endpoint
POST https://api.timekit.io/v2/credentials
Parameters
| Name | In | Type | Required | Default | Description |
|---|---|---|---|---|---|
type |
body | string | yes | 'client-token' or 'server-token' | |
scopes |
body | string | yes | 'global' or 'widget' | |
description |
body | string | yes | Description of these credentials |
Response examples
200
json{
"data": {
"id": "6211bdfb-3e6b-4b5c-b2b2-0a5ee3c3c746",
"type": "client-token",
"description": "BookingJS token",
"token": "CPDqMLOoT4quO7j71jfcD9VlYpJBDPqI",
"scopes": [
"widget"
],
"token_generated_at": "2015-11-25T14:02:48+00:00"
}
}