Skip to Content
GuidesAuthentication

Authentication

The Pouch API is machine-to-machine. Every request is authenticated with a project’s client credentials — there is no end-user login in the API itself. Your backend calls Pouch on behalf of your customers.

Credentials

Each project has its own credential pair:

CredentialDescription
Client IDPublic identifier for the project, e.g. pouch_acme_ab12cd34.
Client secretSecret key, shown once when the credential is created.

Treat the client secret like a password — never ship it to a browser or mobile app. All Pouch calls should be made from your server.

Presenting credentials

Send both values as headers on every request:

curl https://api.pouchlimited.com/api/v1/business/health \ -H "x-client-id: pouch_acme_ab12cd34" \ -H "x-client-secret: <your-client-secret>"
HeaderRequiredDescription
x-client-idyesThe project’s client id
x-client-secretyesThe project’s client secret

Scopes

Credentials carry scopes that gate what they can do. An endpoint checks for the scope it needs and returns 403 if the credential lacks it.

ScopeGrants
customers:readList customers and read their profiles, cashflow and transactions
transactions:writeReclassify or exclude a customer’s transactions
client:readRead your own project/client details
keys:manageManage credentials

Rotating credentials

Rotate a project’s credential from the Pouch Console . Rotation issues a new secret and revokes the old one immediately, so update your server’s configuration before rotating in production.

Authentication errors

StatuscodeMeaning
401invalid_client_credentialsMissing or wrong client id / secret
403credential_inactiveThe credential has been revoked
403client_inactiveThe project/account is not active
403insufficient_scopeThe credential lacks the required scope

See Error responses for the full error shape.