← Back to product·Simulmedia Switchboard Docs · v1 draft·Get started / Authentication
Get started

Authentication

OAuth 2.0 client credentials, machine to machine. Tokens are short-lived JWTs scoped to your organization and roles; send Authorization: Bearer <token> on every request and mint fresh tokens rather than caching near expiry.

ScopeGrants
catalog:readBrowse catalogs, avails, and rates within your agreements
catalog:writeSellers: publish packages, rates, avails
orders:writeCreate, confirm, respond, cancel
orders:approveSellers: decide orders at the review gate
webhooks:manageRegister and allowlist notify endpoints
settlement:readInvoices and make-good ledger on cleared trades

Webhooks the platform sends you carry an HMAC signature in X-Signature computed over the timestamp and body; verify it with your signing key before trusting any event, and reject stale timestamps. Tokens are validated for audience: a token minted for another service will be rejected here.