---
title: Broken 2016 iterations
slug: mihai/broken-2016-iterations
docTags: 
createdAt: 2026-01-23T07:33:02.340Z
---

The VAS Developer API requires an API key and OAuth token to authenticate requests, and features a two-layer authentication model to best protect our data and resources: 

![](https://api.qa.archbee.co/api/optimize/3h8pSJcGUXEi4HGCCYPTA/Jv8Nig3KLPCAxqgynSmZm_g-1074020333-api-dataflow-diagram-small.png)

Credentials to the VAS Developer API are unique to each integration partner. The VAS Integrations team manages and shares your credentials with you during the initial onboarding session. Be sure to keep all credentials and authentication details secure and do not share them in public domains.

::::ExpandableHeading
### Click here for details on generating your OAuth access token!

The VAS Integrations team will share key details to get you started:

- Your `client_id` and `client_secret`, which you need to request a token
- The URL for the request

1. Send your request:

```bash
curl --location 'https://auth.prod.vas.com/connect/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
  --data grant_type=client_credentials \
  --data client_id=your_client_id \
  --data client_secret=your_client_secret \
```

1. Receive your token and expiration details (in seconds) and a `200 OK` response: 

```bash
{
  "access_token":"abcdef...123456",
  "token_type":"Bearer",
  "expires_in":3599
}
```

:::hint{type="info"}
**NOTE:&#x20;**

 

- Access tokens are currently configured to expire in 3599 seconds (almost an hour), so your application will need to authenticate hourly.
- If the request fails, verify that your `client_id` and `client_secret` are correct. [Contact us](docId\:LhduGxnYvpv4W_rz8ESjg) if you need help!
:::

 
::::

All VAS Developer API requests must be made to https\://, and any calls made to http\:// will fail. API requests without the required authentication will also fail.
