generated: '2026-07-17' method: searched source: https://360learning.readme.io/docs/authentication docs: https://360learning.readme.io/docs/authentication summary: types: - oauth2 oauth2_flows: - clientCredentials token_expiry_seconds: 3600 schemes: - name: oauth2 type: oauth2 grant: client_credentials description: >- API v2 uses the OAuth 2.0 Client Credentials grant for server-to-server authentication. Exchange a client_id + client_secret for a bearer access token, then send it as `Authorization: Bearer `. Access tokens are valid for 1 hour (3600s). By default API calls execute with platform-admin-level access; scope it down with credential-level scopes. flows: - flow: clientCredentials tokenUrl: https://app.360learning.com/api/v2/oauth2/token tokenUrl_us: https://app.us.360learning.com/api/v2/oauth2/token token_endpoint: /api/v2/oauth2/token token_type: Bearer token_ttl_seconds: 3600 required_headers: - name: Authorization value: Bearer - name: 360-api-version value: v2.0 credentials: client_id: Unique identifier for the API client (created by a platform admin in the API v2 admin panel). client_secret: Confidential key associated with the client ID. scopes_ref: scopes/360learning-scopes.yml sources: - openapi/360learning-bulk-api.json - openapi/360learning-core-api.json - openapi/360learning-plugin-api.json - openapi/360learning-user-authorized-api.json - openapi/360learning-webhook-api.json