Connect to the member API with client credentials

This tutorial walks an integrator through calling the RAiD member API as their service point, from nothing to a working request. By the end you'll have created a client credential, exchanged it for an access token, and used that token to list every RAiD your service point owns.

Applicability: ARDC RAiD User Interface (to create the credential) and member API (to use it).

Prerequisites:

  • Service Point Admin role for your service point.

  • curl and jq.

  • Know which environment you're working in. Credentials, tokens, and RAiDs are all environment-specific.

Environments:

Environment

Description

demo

A test environment where customers can try new RAiD features before they reach prod.

stage

A stable test environment that mirrors prod, suited to integrators building and testing integrations.

prod

The production environment, where RAiDs minted are real and permanent.


Host

Purpose

IAM host

iam.<environment>.raid.org.au

Issues access tokens

Member API

api.<environment>.raid.org.au

Mint/read/update RAiDs

Step 1: Create client credentials

  1. Log in to the RAiD User Interface.

  2. Open the hamburger menu and select Manage service points, then select the service point you administer.

  3. In the left-hand sidebar of the service point page, select Client credentials.

  4. Expand Create client credential, enter a Label to help you recognise this credential later (e.g. repository-integration), and click Create.

  5. A Credential created panel shows the Client ID and Secret, masked by default. Store the secret securely now. You can view it again later, but only while the credential remains active.

A service point may hold at most 10 active credentials.

Step 2: Exchange your credential for an access token

bash

Bash
ENV=demo
CLIENT_ID=YOUR_CLIENT_ID
CLIENT_SECRET=YOUR_CLIENT_SECRET

TOKEN=$(curl -s -X POST \
  "https://iam.$ENV.raid.org.au/realms/raid/protocol/openid-connect/token" \
  -d "client_id=$CLIENT_ID" \
  -d "client_secret=$CLIENT_SECRET" \
  -d "grant_type=client_credentials" \
  | jq -r .access_token)

Unlike a personal API token, this has no refresh token. Request a new one the same way when it expires.

Step 3: List your service point's RAiDs

bash

Bash
curl -s "https://api.$ENV.raid.org.au/raid/" \
  -H "Authorization: Bearer $TOKEN" | jq .

You don't need to pass a service point ID or group ID: the token itself carries your service point's identity (via the service_point_group_id claim), and the member API returns every RAiD your service point owns, including any that are embargoed.

See also