Skip to main content

Authentication — API Key + OAuth

Two ways to authorise: server-side, and acting for a user.

Advanced· 6 min read· Last updated: 2026-05-05· 18 people found this helpful
**API key — for server-side work.** 1. Settings → Developers → API keys → “New key” → choose the scope (read / write / admin). 2. Store the key as a secret — never show it to anyone. 3. Send `Authorization: Bearer YOUR_KEY` on every request. ```bash curl https://api.glanevo.com/v1/appointments \ -H "Authorization: Bearer sk_live_xxx" ``` **OAuth 2.0 — on a user's behalf.** Third-party applications (the Glanevo Zapier connector, for instance) use this flow: 1. Register an **OAuth app** in the Glanevo developer panel to get a `client_id` and `client_secret`. 2. Send the user to `https://glanevo.com/oauth/authorize?client_id=...&scope=appointments:read`. 3. The user approves and is returned to your callback URL with a `code` parameter. 4. Exchange the `code` at the token endpoint for an `access_token` (valid for one hour). 5. Use the `refresh_token` for longer-lived access. **Scopes:** - `appointments:read`, `appointments:write` - `customers:read`, `customers:write` - `payments:read` - `admin` (everything) 🔒 Revoking a key: developer panel → “Revoke” — it stops working immediately.

Was this article helpful?