client_id and client_secret issued with your API credentials for an access token, then send that token as a bearer token with each API call. You can start using the API without running your own server, since Client Credentials requires no callback URL to receive an authorization code.
For an introduction to OAuth2, see the primers from DigitalOcean and oauth.net.
To exchange your credentials for a token, see Get Token. Once you have an access token you can make API calls to any documented endpoint.
Access tokens expire. The expires_in value in the token response gives the token’s lifetime in seconds. Request a new token with your client credentials when the current one expires.
Migrating from the password grant
The token endpoint no longer supports the Resource Owner Password Credentials flow. If your integration still sends a username and password, stop sending both and setgrant_type to client_credentials. Your client_id and client_secret stay the same.