Get an access token
The host domain for OAuth endpoints is login.pinecone.io.
PINECONE_CLIENT_ID="YOUR_CLIENT_ID"
PINECONE_CLIENT_SECRET="YOUR_CLIENT_SECRET"
# NOTES:
# - Base URL is login.pinecone.io.
# - When including environment variables (as shown here),
# surround the request body in double quotes (not single
# quotes). Then, in the JSON, escape double quotes with
# a backslash.
curl -X POST "https://login.pinecone.io/oauth/token" \
-H "X-Pinecone-Api-Version: 2025-04" \
-H "Content-Type: application/json" \
-d "{
\"grant_type\": \"client_credentials\",
\"client_id\": \"$PINECONE_CLIENT_ID\",
\"client_secret\": \"$PINECONE_CLIENT_SECRET\",
\"audience\": \"https://api.pinecone.io/\"
}"{
"access_token": "...",
"expires_in": 1800,
"token_type": "Bearer"
}POST /oauth/token
Request body
Section titled “Request body”client_id(body, string, required) — The service account's client ID.client_secret(body, string, required) — The service account's client secret.grant_type(body, string, required) — The type of grant to use.audience(body, string, required) — The audience for the token.
Responses
Section titled “Responses”200— A response that contains the access token.400— Invalid request.401— Unauthorized.403— Forbidden.429— Too many requests.500— Internal server error.501— Not implemented.503— Service unavailable.