generated: '2026-07-17' method: searched source: openapi/ankorstore-astral-openapi-original.yml, openapi/ankorstore-main-openapi-original.yml docs: https://ankorstore.github.io/api-docs/#section/Authentication notes: >- The Ankorstore Public API uses OAuth2 Client Credentials. Exchange client_id/client_secret at POST https://www.ankorstore.com/oauth/token (sandbox: https://www.public.ankorstore-sandbox.com/oauth/token) with scope=* to receive a Bearer token valid for 3600s. The /oauth/token endpoint is rate-limited to 60 requests/hour. Applications and their client credentials are created in the Integrations area of the Ankorstore account (https://ankorstore.com/account/integrations). The ASTRAL spec additionally declares a session-cookie apiKey scheme (ankorstore_session) for browser-context calls. summary: types: - apiKey - oauth2 api_key_in: - cookie oauth2_flows: - clientCredentials schemes: - name: CookieKey type: apiKey in: cookie parameter: ankorstore_session sources: - openapi/ankorstore-astral-openapi-original.yml - name: ProductionOAuth2ClientCredentials type: oauth2 flows: - flow: clientCredentials tokenUrl: https://www.ankorstore.com/oauth/token scopes: 0 sources: - openapi/ankorstore-main-openapi-original.yml