/portalAPI/OAuth/*

2 min. readlast update: 10.09.2026

This article will encompass all portalAPI calls that are related to /portalAPI/OAuth/* endpoints

 

If you are new to working with ThreatLocker PortalAPI endpoints and/or have questions regarding authentication and terminology used throughout this article, please look through the following guide:

Getting Started with ThreatLocker PortalAPIs

 

Table of Contents

Token

 

Note: This feature is currently in Beta. Please use betaportalapi as the prefix instead of portalapi on ALL API calls when using OAuth authentication.

 

Token

https://betaportalapi.INSTANCE.threatlocker.com/portalapi/OAuth/Token

  • Method: POST
  • Description: This API generates a new OAuth token used for API authentication with a Bearer token instead of an API Key. To use this API, an API User must use OAuth 2.0 authentication with valid clientId and clientSecret values. For more information on creating an API User using the OAuth 2.0 authentication method, see the KB article below:

API Users | ThreatLocker Help Center

  • Required Body/Parameters
    • Fields
      • clientId: This field determines which API User's token will be refreshed. Note that this ID differs from the APIUserId found in the Portal and is visible only when creating the API User or generating new OAuth credentials; it should be stored securely.
        • Expects a GUID in format: "00000000-0000-0000-0000-000000000000"
      • clientSecret: This field determines the API User's secret key used for authentication/token refreshing. Note that this value is visible only when creating the API User or generating new OAuth credentials; it should be stored securely.
        • Expects: Text input of the client's secret key
Required body
{
    "clientId": "<GUID>",
    "clientSecret": "<String>"
}
  • Optional Body/Parameters
    • N/A
  • Permission Requirements
    • N/A
Sample response body: Use the String value returned in the accessToken field as the value for your Bearer token/API Authentication
{
    "accessToken": "<String>",
    "tokenType": "Bearer",
    "expiresInSeconds": <Integer>,
    "scope": null
}
Was this article helpful?