Authentication
The Pouch API is machine-to-machine. Every request is authenticated with a project’s client credentials — there is no end-user login in the API itself. Your backend calls Pouch on behalf of your customers.
Credentials
Each project has its own credential pair:
| Credential | Description |
|---|---|
| Client ID | Public identifier for the project, e.g. pouch_acme_ab12cd34. |
| Client secret | Secret key, shown once when the credential is created. |
Treat the client secret like a password — never ship it to a browser or mobile app. All Pouch calls should be made from your server.
Presenting credentials
Send both values as headers on every request:
curl https://api.pouchlimited.com/api/v1/business/health \
-H "x-client-id: pouch_acme_ab12cd34" \
-H "x-client-secret: <your-client-secret>"| Header | Required | Description |
|---|---|---|
x-client-id | yes | The project’s client id |
x-client-secret | yes | The project’s client secret |
Scopes
Credentials carry scopes that gate what they can do. An endpoint checks for the scope
it needs and returns 403 if the credential lacks it.
| Scope | Grants |
|---|---|
customers:read | List customers and read their profiles, cashflow and transactions |
transactions:write | Reclassify or exclude a customer’s transactions |
client:read | Read your own project/client details |
keys:manage | Manage credentials |
Rotating credentials
Rotate a project’s credential from the Pouch Console . Rotation issues a new secret and revokes the old one immediately, so update your server’s configuration before rotating in production.
Authentication errors
| Status | code | Meaning |
|---|---|---|
401 | invalid_client_credentials | Missing or wrong client id / secret |
403 | credential_inactive | The credential has been revoked |
403 | client_inactive | The project/account is not active |
403 | insufficient_scope | The credential lacks the required scope |
See Error responses for the full error shape.