The host domain for OAuth endpoints is `login.pinecone.io`.

```bash curl theme={null}
PINECONE_CLIENT_ID="YOUR_CLIENT_ID"
PINECONE_CLIENT_SECRET="YOUR_CLIENT_SECRET"

# NOTES:
# - Base URL is login.pinecone.io. 
# - When including environment variables (as shown here), 
#   surround the request body in double quotes (not single
#   quotes). Then, in the JSON, escape double quotes with
#   a backslash.
curl -X POST "https://login.pinecone.io/oauth/token" \
     -H "X-Pinecone-Api-Version: 2025-04" \
     -H "Content-Type: application/json" \
     -d "{
           \"grant_type\": \"client_credentials\",
           \"client_id\": \"$PINECONE_CLIENT_ID\",
           \"client_secret\": \"$PINECONE_CLIENT_SECRET\",
           \"audience\": \"https://api.pinecone.io/\"
         }"
```

```json curl theme={null}
{
  "access_token": "...",
  "expires_in": 1800,
  "token_type": "Bearer"
}
```

`POST /oauth/token`

:::code-group
```bash title="cURL"
curl --request POST \
  --url https://login.pinecone.io/oauth/token \
  --header 'Content-Type: application/json' \
  --data '{
  "audience": "https://api.pinecone.io/",
  "client_id": "I1r8m4i6jX9JTFYk0t3q85HWzciEgcA5",
  "client_secret": "EriX...j2ci",
  "grant_type": "client_credentials"
}'
```

```json title="200"
{
  "access_token": "eyJz93a...k4laUWw",
  "expires_in": 1800,
  "token_type": "Bearer"
}
```
:::

## Body

- `client_id` (body, string, required) — The service account's client ID.
- `client_secret` (body, string, required) — The service account's client secret.
- `grant_type` (body, string, required) — The type of grant to use.
- `audience` (body, string, required) — The audience for the token.

## Response

- `200` — A response that contains the access token.
- `400` — Invalid request.
- `401` — Unauthorized.
- `403` — Forbidden.
- `429` — Too many requests.
- `500` — Internal server error.
- `501` — Not implemented.
- `503` — Service unavailable.

## Related pages

- [List service accounts](./admin-2-2026-07-admin-service-accounts-list-service-accounts.md)
- [Create a service account](./admin-2-2026-07-admin-service-accounts-create-a-service-account.md)
- [Get service account details](./admin-2-2026-07-admin-service-accounts-get-service-account-details.md)
- [Delete a service account](./admin-2-2026-07-admin-service-accounts-delete-a-service-account.md)
- [Update a service account](./admin-2-2026-07-admin-service-accounts-update-a-service-account.md)
- [Rotate a service account's OAuth client secret](./admin-2-2026-07-admin-service-accounts-rotate-a-service-accounts-oauth-client-secret.md)
- [Create a service account](./admin-2-2026-04-admin-create-service-account.md)
- [List service accounts](./admin-2-2026-04-admin-list-service-accounts.md)
- [Get service account details](./admin-2-2026-04-admin-fetch-service-account.md)
- [Update a service account](./admin-2-2026-04-admin-update-service-account.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
