Authentication
This guide describes how to authenticate your requests to the Jasper API.
Authenticate Public API requests with either a workspace-level API key or user-level OAuth.
- Workspace API key: Use an API key for unattended server-to-server scripts.
- OAuth: Use OAuth when your application needs to act on behalf of a specific Jasper user.
Authenticate with a workspace API key
API key management is limited to users with the Admin or Developer role in a workspace.
Admins and Developers can generate API tokens in their workspace via the settings/dev-tools/tokens page.

Pass the generated API token in the X-API-Key HTTP header:
curl --request GET \
--url https://api.jasper.ai/v1/templates \
--header 'X-API-Key: YOUR_JASPER_API_KEY' \
--header 'accept: application/json' \
--header 'content-type: application/json'
Heads upYour API key is a secret. Do not share it or expose it in client-side applications. Route requests to the Jasper API through your backend server, and make all requests over HTTPS.
Authenticate with OAuth
Use OAuth when your application needs permission to access Jasper on behalf of a user. Jasper supports the Authorization Code flow with PKCE (Proof Key for Code Exchange) and does not support the Client Credentials grant.
Each OAuth token is tied to the Jasper user and workspace that approve access. For unattended server-to-server scripts, use a workspace API key instead.
OAuth configuration
| Setting | Value |
|---|---|
| Authorization URL | https://api.jasper.ai/oauth2/authorize |
| Token URL | https://api.jasper.ai/oauth2/token |
| API base URL | https://api.jasper.ai/v1 |
| Discovery document | https://api.jasper.ai/.well-known/oauth-authorization-server |
| PKCE method | S256 |
| Client authentication | HTTP Basic header |
Create an OAuth client
Create an OAuth client once for each integration.
- Open Workspace Settings in Jasper.
- Under Developer tools, select OAuth clients, or open OAuth clients.
- Click Add OAuth client.
- Enter a client name, select the allowed scopes, and add one to three redirect URIs.
- Click Create client and copy the client ID and client secret.
Your workspace must have Jasper API access, and you need the Admin, IT Admin, or Developer role to create a client. Contact your Jasper account team if Developer tools is not available.
Heads UpThe client secret is shown only once. Store it in a password manager or secrets vault before closing the dialog. Resetting a secret immediately invalidates the previous secret.
Choose scopes
Tokens can request only scopes enabled on the OAuth client. API endpoints list their accepted scopes in the Authorization section of the API reference.
| Scope | Access | Use it for |
|---|---|---|
user | View and create Audiences, Projects, Knowledge Base items, Style Guides, and Brand Voices; generate content using IQ assets. | Integrations that generate content or create or update Jasper resources. |
user:read | Read the Audiences, Projects, Documents, Knowledge Base items, Style Guides, and Brand Voices visible to the user. | Reporting, search, and sync. Create, update, and delete calls, and POST /v1/command, require user. |
Get an OAuth token with cURL
Use the Authorization Code flow with PKCE in your own application. Before you start, create an OAuth client and configure your application's callback URL as a redirect URI.
- Generate a random
code_verifier(43 to 128 characters) and derivecode_challenge = BASE64URL(SHA256(code_verifier)). Redirect the user's browser to:
https://api.jasper.ai/oauth2/authorize
?response_type=code
&client_id=$CLIENT_ID
&redirect_uri=https%3A%2F%2Fyourapp.example.com%2Fcallback
&scope=user
&state=$RANDOM_STATE
&code_challenge=$CODE_CHALLENGE
&code_challenge_method=S256After the user clicks Confirm, Jasper redirects to your redirect_uri with code and state query parameters. Check that state matches what you sent.
- Exchange the authorization code for tokens:
curl -X POST https://api.jasper.ai/oauth2/token \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-d grant_type=authorization_code \
-d code="$CODE" \
-d redirect_uri=https://yourapp.example.com/callback \
-d code_verifier="$CODE_VERIFIER"-u sends the client ID and secret as an HTTP Basic header. The code expires after 10 minutes and can be used once.
- Call the API with the access token:
curl "https://api.jasper.ai/v1/tones?page=1&size=10" \
-H "Authorization: Bearer $ACCESS_TOKEN"- Refresh the token before the access token expires:
curl -X POST https://api.jasper.ai/oauth2/token \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-d grant_type=refresh_token \
-d refresh_token="$REFRESH_TOKEN"Save the new refresh token from the response. The one you just used no longer works.
- Revoke a token when a user disconnects:
curl -X POST https://api.jasper.ai/oauth2/revoke \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-d token="$REFRESH_TOKEN" \
-d token_type_hint=refresh_tokenGet an OAuth token in Postman
Configure OAuth on a Postman collection so its requests inherit the token.
- Open the collection's Authorization tab.
- Set Auth Type to OAuth 2.0.
- Set Add auth data to to Request Headers and leave Header Prefix as
Bearer. - Select Get New Access Token and enter the following values:
| Postman field | Value |
|---|---|
| Grant Type | Authorization Code (With PKCE) |
| Callback URL | https://oauth.pstmn.io/v1/callback |
| Auth URL | https://api.jasper.ai/oauth2/authorize |
| Access Token URL | https://api.jasper.ai/oauth2/token |
| Client ID | Your OAuth client ID |
| Client Secret | Your OAuth client secret |
| Code Challenge Method | SHA-256 |
| Scope | user or user:read |
| Client Authentication | Send as Basic Auth header |
Add the Postman callback URL as a redirect URI on your OAuth client. For Postman web, use https://oauth.pstmn.io/v1/browser-callback instead.
- Click Get New Access Token, sign in to Jasper, and select Confirm on the consent screen.
- In Postman, click Use Token and enable Auto-refresh token.
The consent screen identifies the Jasper workspace that the token can access. If it is the wrong workspace, select Deny, switch workspaces in Jasper, and repeat the authorization flow.
Call the API with an access token
Send the access token in the Authorization header. For example, list Brand Voices (called tones in the API):
curl --request GET \
--url 'https://api.jasper.ai/v1/tones?page=1&size=10' \
--header 'Authorization: Bearer YOUR_ACCESS_TOKEN'A successful request returns 200 OK.
Manage OAuth tokens
| Credential | Lifetime | Notes |
|---|---|---|
| Authorization code | 10 minutes | Single use. |
| Access token | 24 hours | Send as Authorization: Bearer. |
| Refresh token | 30 days | Rotates with every refresh. |
| Client secret | No expiry | Valid until you reset it. |
The token endpoint returns an access token and refresh token:
{
"access_token": "eyJhbGciOiJIUzI1NiIs...",
"token_type": "Bearer",
"expires_in": 86400,
"refresh_token": "eyJhbGciOiJIUzI1NiIs...",
"scope": "user"
}Refresh tokens rotate: each refresh invalidates the prior access-token and refresh-token pair. Jasper keeps one live session for each client, user, and workspace, so authorizing the same client again also invalidates earlier tokens. Create a separate OAuth client for each integration.
Troubleshooting OAuth
| What you see | Likely cause | Fix |
|---|---|---|
| No Developer tools section or "You do not have access to this page." | Your workspace does not have API access, or your role is not Admin, IT Admin, or Developer. | Ask a workspace admin to change your role, or contact Jasper to enable API access. |
invalid_request immediately after requesting a new access token | The callback URL does not exactly match a redirect URI on the OAuth client. | Add the exact callback URL to the client, including https:// and the full path. |
invalid_client | The client ID or secret is incorrect, the secret was reset, or the client was removed. | Copy the client ID again, or reset the secret and update your integration. |
Updated 3 days ago
