Ontdekken


Thuis Over Prijzen Studio Api Contact

Taal

logo

powered by xwms

Terug naar overzicht

Supportgroepen

Clients & API

OAuth, tokens, scopes, API-toegang en clientinstellingen.

The XWMS API allows developers to integrate authentication, user management, and account-related services directly into their own applications.

api integration authentication

To access the API, you first create an XWMS account, activate a client plan, and then create a client application in the dashboard to receive credentials.

api setup client

API credentials are your client ID and client secret, used to identify and authorize your application when communicating with XWMS.

api security client

Yes. You can regenerate the secret in client settings. After rotation, update your application immediately to avoid authentication failures.

client security api

An access token is a temporary credential used to call protected API endpoints on behalf of a user or client.

tokens oauth api

Supported flows include common OAuth patterns such as Authorization Code flow. Always use the flow that matches your app type and security requirements.

oauth api setup

A client is an application registration that connects to the XWMS API and defines credentials, redirects, and permissions.

client api setup

Yes. You can test locally using tools like Postman or curl, as long as your credentials and callback URLs are configured correctly.

api testing setup

SDK availability depends on supported languages and current platform roadmap.

api sdk docs

Store API keys on secure backend systems only, preferably in protected environment variables and secret managers.

security api keys

Check response payloads, status codes, request parameters, and server-side logs to identify the root cause.

api debugging logs

Yes. Logging request and response metadata helps monitor integrations, performance, and incident investigations.

api logs usage

Yes. XWMS monitors suspicious traffic patterns and may restrict abusive behavior to protect platform stability.

security api monitoring

Most secured API endpoints require X-Client-Id, X-Client-Secret, and X-Client-Domain headers. These identify the client, authenticate the secret, and let XWMS verify that the request is coming from an allowed domain configuration.

api headers client-credentials

XWMS resolves the client and domain from the request headers, verifies that the client secret is active, checks that the domain is allowed, and enforces domain settings such as active status, authentication access, API access, server IP allowlists, and test or live mode rules.

api client-credentials security

Yes. API access is tied to client domain settings, so a domain can be active or inactive, allowed or blocked for authentication, allowed or blocked for API access, and optionally restricted through server IP allowlist logic.

api domains security

Live mode expects HTTPS so credentials, tokens, and user data are not sent over insecure production traffic. HTTP is mainly tolerated for test-mode or local development style configurations.

api https live-mode

The sign-token and sign-token-verify endpoints are configured as free. Other endpoints such as user info, user address, countries, or default paid API requests can be billed by usage.

api oauth pricing

XWMS Clients Basic is free and intended for a single client workspace with up to three domains, OAuth sign-in, and an included monthly request allowance before paid endpoint usage applies.

api basic pricing

XWMS Clients Enterprise is the paid XWMS Clients plan at EUR 29 per month. It unlocks XWMS Clients without hard limits for clients, domains, members, roles and secrets, with usage-based API billing and support.

api enterprise pricing

Live support

Begin een gesprek

Welkom terug. Start een ticket of laat je vraag achter.