Authentication

This guide describes how to authenticate your requests to the Jasper API.

Authenticate Public API requests with either a workspace-level API key or user-level OAuth.

  • Workspace API key: Use an API key for unattended server-to-server scripts.
  • OAuth: Use OAuth when your application needs to act on behalf of a specific Jasper user.

Authenticate with a workspace API key

API key management is limited to users with the Admin or Developer role in a workspace.

Admins and Developers can generate API tokens in their workspace via the settings/dev-tools/tokens page.

Pass the generated API token in the X-API-Key HTTP header:

curl --request GET \
     --url https://api.jasper.ai/v1/templates \
     --header 'X-API-Key: YOUR_JASPER_API_KEY' \
     --header 'accept: application/json' \
     --header 'content-type: application/json'
ℹ️

Heads up

Your API key is a secret. Do not share it or expose it in client-side applications. Route requests to the Jasper API through your backend server, and make all requests over HTTPS.

Authenticate with OAuth

Use OAuth when your application needs permission to access Jasper on behalf of a user. Jasper supports the Authorization Code flow with PKCE (Proof Key for Code Exchange) and does not support the Client Credentials grant.

Each OAuth token is tied to the Jasper user and workspace that approve access. For unattended server-to-server scripts, use a workspace API key instead.

OAuth configuration

SettingValue
Authorization URLhttps://api.jasper.ai/oauth2/authorize
Token URLhttps://api.jasper.ai/oauth2/token
API base URLhttps://api.jasper.ai/v1
Discovery documenthttps://api.jasper.ai/.well-known/oauth-authorization-server
PKCE methodS256
Client authenticationHTTP Basic header

Create an OAuth client

Create an OAuth client once for each integration.

  1. Open Workspace Settings in Jasper.
  2. Under Developer tools, select OAuth clients, or open OAuth clients.
  3. Click Add OAuth client.
  4. Enter a client name, select the allowed scopes, and add one to three redirect URIs.
  5. Click Create client and copy the client ID and client secret.

Your workspace must have Jasper API access, and you need the Admin, IT Admin, or Developer role to create a client. Contact your Jasper account team if Developer tools is not available.

⚠️

Heads Up

The client secret is shown only once. Store it in a password manager or secrets vault before closing the dialog. Resetting a secret immediately invalidates the previous secret.

Choose scopes

Tokens can request only scopes enabled on the OAuth client. API endpoints list their accepted scopes in the Authorization section of the API reference.

ScopeAccessUse it for
userView and create Audiences, Projects, Knowledge Base items, Style Guides, and Brand Voices; generate content using IQ assets.Integrations that generate content or create or update Jasper resources.
user:readRead the Audiences, Projects, Documents, Knowledge Base items, Style Guides, and Brand Voices visible to the user.Reporting, search, and sync. Create, update, and delete calls, and POST /v1/command, require user.

Get an OAuth token with cURL

Use the Authorization Code flow with PKCE in your own application. Before you start, create an OAuth client and configure your application's callback URL as a redirect URI.

  1. Generate a random code_verifier (43 to 128 characters) and derive code_challenge = BASE64URL(SHA256(code_verifier)). Redirect the user's browser to:
https://api.jasper.ai/oauth2/authorize
  ?response_type=code
  &client_id=$CLIENT_ID
  &redirect_uri=https%3A%2F%2Fyourapp.example.com%2Fcallback
  &scope=user
  &state=$RANDOM_STATE
  &code_challenge=$CODE_CHALLENGE
  &code_challenge_method=S256

After the user clicks Confirm, Jasper redirects to your redirect_uri with code and state query parameters. Check that state matches what you sent.

  1. Exchange the authorization code for tokens:
curl -X POST https://api.jasper.ai/oauth2/token \
  -u "$CLIENT_ID:$CLIENT_SECRET" \
  -d grant_type=authorization_code \
  -d code="$CODE" \
  -d redirect_uri=https://yourapp.example.com/callback \
  -d code_verifier="$CODE_VERIFIER"

-u sends the client ID and secret as an HTTP Basic header. The code expires after 10 minutes and can be used once.

  1. Call the API with the access token:
curl "https://api.jasper.ai/v1/tones?page=1&size=10" \
  -H "Authorization: Bearer $ACCESS_TOKEN"
  1. Refresh the token before the access token expires:
curl -X POST https://api.jasper.ai/oauth2/token \
  -u "$CLIENT_ID:$CLIENT_SECRET" \
  -d grant_type=refresh_token \
  -d refresh_token="$REFRESH_TOKEN"

Save the new refresh token from the response. The one you just used no longer works.

  1. Revoke a token when a user disconnects:
curl -X POST https://api.jasper.ai/oauth2/revoke \
  -u "$CLIENT_ID:$CLIENT_SECRET" \
  -d token="$REFRESH_TOKEN" \
  -d token_type_hint=refresh_token

Get an OAuth token in Postman

Configure OAuth on a Postman collection so its requests inherit the token.

  1. Open the collection's Authorization tab.
  2. Set Auth Type to OAuth 2.0.
  3. Set Add auth data to to Request Headers and leave Header Prefix as Bearer.
  4. Select Get New Access Token and enter the following values:
Postman fieldValue
Grant TypeAuthorization Code (With PKCE)
Callback URLhttps://oauth.pstmn.io/v1/callback
Auth URLhttps://api.jasper.ai/oauth2/authorize
Access Token URLhttps://api.jasper.ai/oauth2/token
Client IDYour OAuth client ID
Client SecretYour OAuth client secret
Code Challenge MethodSHA-256
Scopeuser or user:read
Client AuthenticationSend as Basic Auth header

Add the Postman callback URL as a redirect URI on your OAuth client. For Postman web, use https://oauth.pstmn.io/v1/browser-callback instead.

  1. Click Get New Access Token, sign in to Jasper, and select Confirm on the consent screen.
  2. In Postman, click Use Token and enable Auto-refresh token.

The consent screen identifies the Jasper workspace that the token can access. If it is the wrong workspace, select Deny, switch workspaces in Jasper, and repeat the authorization flow.

Call the API with an access token

Send the access token in the Authorization header. For example, list Brand Voices (called tones in the API):

curl --request GET \
  --url 'https://api.jasper.ai/v1/tones?page=1&size=10' \
  --header 'Authorization: Bearer YOUR_ACCESS_TOKEN'

A successful request returns 200 OK.

Manage OAuth tokens

CredentialLifetimeNotes
Authorization code10 minutesSingle use.
Access token24 hoursSend as Authorization: Bearer.
Refresh token30 daysRotates with every refresh.
Client secretNo expiryValid until you reset it.

The token endpoint returns an access token and refresh token:

{
  "access_token": "eyJhbGciOiJIUzI1NiIs...",
  "token_type": "Bearer",
  "expires_in": 86400,
  "refresh_token": "eyJhbGciOiJIUzI1NiIs...",
  "scope": "user"
}

Refresh tokens rotate: each refresh invalidates the prior access-token and refresh-token pair. Jasper keeps one live session for each client, user, and workspace, so authorizing the same client again also invalidates earlier tokens. Create a separate OAuth client for each integration.

Troubleshooting OAuth

What you seeLikely causeFix
No Developer tools section or "You do not have access to this page."Your workspace does not have API access, or your role is not Admin, IT Admin, or Developer.Ask a workspace admin to change your role, or contact Jasper to enable API access.
invalid_request immediately after requesting a new access tokenThe callback URL does not exactly match a redirect URI on the OAuth client.Add the exact callback URL to the client, including https:// and the full path.
invalid_clientThe client ID or secret is incorrect, the secret was reset, or the client was removed.Copy the client ID again, or reset the secret and update your integration.

Did this page help you?