Available Grant Types

Configure Authentication: Obtaining A Session

The SuiteCRM API requires that a client has an active session to consume the API. Sessions are acquired by authenticating with the OAuth 2 Server, using one of the available grant types.

Configure Grant Types

Before you can consume the API, you must first configure SuiteCRM to grant access to a client. SuiteCRM 7.10 provides an administrative panel, through which you can add clients and revoke tokens. To configure the grant types, select the admin panel, and then select OAuth2 Clients and Tokens:

Configure SuiteCRM API

Available Grant Types

SuiteCRM Version Available Grant Types


Password Grant, Refresh Token Grant


Password Grant, Client credentials Grant, Refresh Token Grant

Create a new grant

Client Credentials Grant

A client credentials grant is the simplest of all of the grants types, this grant is used to authenticate a machine or service. Select new client credentials client:

Create a new client credentials grant

Begin configuring the grant:

Create a new Client

Field Description


This makes it easy to identify the client.


Defines the client_secret which is posted to the server during authentication.

Is Confidential

A confidential client is an application that is capable of keeping a client password confidential to the world.

Associated User

Limits the client access to CRM, by associating the client with the security privileges of a user.

The 'secret' will be hashed when saved, and will not be accessible later. The 'id' is created by SuiteCRM and will be visible once the client is saved.

View a Client Credentials Client

Authentication with Client Credentials

POST /Api/access_token

Required parameters

param value







Example Request (PHP):
$ch = curl_init();
$header = array(
    'Content-type: application/vnd.api+json',
    'Accept: application/vnd.api+json',
$postStr = json_encode(array(
    'grant_type' => 'client_credentials',
    'client_id' => '3D7f3fda97-d8e2-b9ad-eb89-5a2fe9b07650',
    'client_secret' => 'client_secret',
$url = 'https://path-to-instance/Api/access_token';
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'POST');
curl_setopt($ch, CURLOPT_POSTFIELDS, $postStr);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPHEADER, $header);
$output = curl_exec($ch);
Example Response:
token_type the Bearer token value


an integer representing the TTL of the access token


a JWT signed with the authorization server’s private key. It is required that you include this in the HTTP headers, each time you make a request to the API

You can store the bearer token in a database and use in your requests like this:

$header = array(
   'Content-type: application/vnd.api+json',
   'Accept: application/vnd.api+json',
   'Authorization: Bearer ' . $your_saved_access_token

Password Grant

A password grant is used for allow users to log into SuiteCRM with a username and a password. Select new password client:

Create a Password Client

Begin configuring grant:

Create a new Client


This makes it easy to identify the client.


Defines the client_secret which is posted to the server during authentication.

Is Confidential

A confidential client is an application that is capable of keeping a client password confidential to the world.

The 'secret' will be hashed when saved, and will not be accessible later. The 'id' is created by SuiteCRM and will be visible once the client is saved.

View a password grant client

Authentication with Password Grant

POST /Api/access_token

Required parameters

param value











Please change the values in bold to match your chosen authentication details.

Example Request (PHP):
$ch = curl_init();
$header = array(
    'Content-type: application/vnd.api+json',
    'Accept: application/vnd.api+json',
$postStr = json_encode(array(
    'grant_type' => 'password',
    'client_id' => '3D7f3fda97-d8e2-b9ad-eb89-5a2fe9b07650',
    'client_secret' => 'client_secret',
    'username' => 'admin',
    'password' => 'admin',
$url = 'https://path-to-instance/Api/access_token';
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'POST');
curl_setopt($ch, CURLOPT_POSTFIELDS, $postStr);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPHEADER, $header);
$output = curl_exec($ch);
Example Response:
token_type the Bearer token value


an integer representing the TTL of the access token


a JWT signed with the authorization server’s private key. It is required that you include this in the HTTP headers, each time you make a request to the API


an encrypted payload that can be used to refresh the access token when it expires.

You can store the bearer token in a database and use in your requests like this:

$header = array(
   'Content-type: application/vnd.api+json',
   'Accept: application/vnd.api+json',
   'Authorization: Bearer ' . $your_saved_access_token

Refresh Token Grant

A refresh token grant is used if you already have a refresh token generated from password grant. It is used to get a new access token.

"grant_type": "refresh_token",
"client_id": "Client Id",
"client_secret": "Client Secret",
"refresh_token": "refresh token" (returned with password grant)

Required parameters

param value




Client ID


Client Secret


refresh token

Please change the values in bold to match your chosen authentication details. ß .Example Request (PHP):

$ch = curl_init();
$header = array(
    'Content-type: application/vnd.api+json',
    'Accept: application/vnd.api+json',
$postStr = json_encode(array(
    'grant_type' => 'refresh_token',
    'client_id' => '3D7f3fda97-d8e2-b9ad-eb89-5a2fe9b07650',
    'client_secret' => 'client_secret',
    'refresh_token' => 'refresh_token',
$url = 'https://path-to-instance/Api/access_token';
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'POST');
curl_setopt($ch, CURLOPT_POSTFIELDS, $postStr);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPHEADER, $header);
$output = curl_exec($ch);
Example Response:
token_type the Bearer token value


an integer representing the TTL of the access token


a JWT signed with the authorization server’s private key. It is required that you include this in the HTTP headers, each time you make a request to the API


an encrypted payload that can be used to refresh the access token when it expires.

Content is available under GNU Free Documentation License 1.3 or later unless otherwise noted.