Generate a token in the playground
- Open OAuth integrations in the console and create an integration with the required scopes.
- Save the Client ID and client secret shown after creation. The secret is displayed only once; existing integration secrets cannot be recovered.
- Open the GraphQL playground and choose “Generate token”. In the dialog, enter the saved Client ID and secret, and select only scopes granted to the integration.
- Select “Generate integration token”. The token is applied to GraphiQL automatically, the dialog closes, and the secret is cleared. Reuse the saved credentials to generate another token when the current one expires.
The Client ID and secret are used only in this page's memory and sent over HTTPS to the configured Cognito endpoint. They are not stored in a URL, browser storage, or logs. Closing the dialog cancels generation and clears the secret. An integration token is limited to its granted scopes and integration identity. Alternatively, open “Token API” in the account section of the portal left menu (open navigation on mobile) and copy the current ID token used for API requests; it has the signed-in user's permissions and does not elevate them. The menu shows the current JWT token expiration, not your logout time — refresh can extend it. Expired tokens cannot be copied.
The credential dialog shown after integration creation lets you copy the Client ID and a curl request example. Existing client secrets cannot be recovered.
Exchange a token on your server
You can also exchange credentials on a server. Use the exact token endpoint URL and scopes shown for the integration; never embed the secret in browser code or source control.
curl -X POST "$OAUTH_TOKEN_URL" -H "Content-Type: application/x-www-form-urlencoded" --data-urlencode "grant_type=client_credentials" --data-urlencode "client_id=$CLIENT_ID" --data-urlencode "client_secret=$CLIENT_SECRET" --data-urlencode "scope=$SCOPES"
SCOPES is a space-separated list of scopes granted to the integration, for example smspipe/devices.read.
Read the access_token value and add it as Authorization: Bearer ....
Client example
curl -X POST "https://api.smsport.app/graphql" -H "Authorization: Bearer $ACCESS_TOKEN" -H "Content-Type: application/json" --data '{"query":"query Workspaces($after: String) {\n workspaces(first: 20, after: $after) {\n nodes { id displayName status }\n pageInfo { hasNextPage endCursor }\n }\n}","variables":{}}'
Copy an id from workspaces.nodes and follow the workspace → device → SMS walkthrough. Reading devices needs smspipe/devices.read, sending needs smspipe/messages.write, and checking status needs smspipe/messages.read. Select only scopes granted to the integration.