Skip to main content
Pinecone Docs

Search documentation

Type to search this documentation.

On this pageOverview

Create an access token

The host domain for OAuth endpoints is login.pinecone.io.

JavaScript
// Requires Node.js SDK v8.2.0 or later
import { AdminClient } from '@pinecone-database/pinecone';

// You don't call this endpoint directly when using the SDK. The AdminClient
// exchanges your service account credentials for an access token on the first
// admin request and reuses it for subsequent calls.
const admin = new AdminClient({
  clientId: 'YOUR_CLIENT_ID',
  clientSecret: 'YOUR_CLIENT_SECRET',
});

const { data: projects } = await admin.projects.list();
console.log(projects);
Go
// Requires Go SDK v6.0.0 or later
package main

import (
    "context"
    "fmt"
    "log"

    "github.com/pinecone-io/go-pinecone/v6/pinecone"
)

func main() {
    ctx := context.Background()

    // You don't call this endpoint directly when using the SDK. The AdminClient
    // exchanges your service account credentials for an access token.
    adminClient, err := pinecone.NewAdminClientWithContext(ctx, pinecone.NewAdminClientParams{
        ClientId:     "YOUR_CLIENT_ID",
        ClientSecret: "YOUR_CLIENT_SECRET",
    })
    if err != nil {
        log.Fatalf("Failed to create AdminClient: %v", err)
    }

    projects, err := adminClient.Project.List(ctx)
    if err != nil {
        log.Fatalf("Failed to list projects: %v", err)
    }
    fmt.Printf("Found %v projects\n", len(projects))
}
curl
curl "https://login.pinecone.io/oauth/token" \ # Note: Base URL is login.pinecone.io
	-H "X-Pinecone-Api-Version: 2026-04" \
	-H "Content-Type: application/json" \
	-d '{
		"grant_type": "client_credentials",
		"client_id": "YOUR_CLIENT_ID",
		"client_secret": "YOUR_CLIENT_SECRET",
		"audience": "https://api.pinecone.io/"
	}'
curl
{
    "access_token":"YOUR_ACCESS_TOKEN",
    "expires_in":86400,
    "token_type":"Bearer"
}

POST /oauth/token

  • X-Pinecone-Api-Version (header, string, required) — Required date-based version header
  • client_id (body, string, required) — The service account's client ID.
  • client_secret (body, string, required) — The service account's client secret.
  • grant_type (body, string, required) — The type of grant to use.
  • audience (body, string, required) — The audience for the token.
  • 200 — A response that contains the access token.
  • 400 — Invalid request.
  • 401 — Unauthorized.
  • 403 — Forbidden.
  • 429 — Too many requests.
  • 500 — Internal server error.
  • 501 — Not implemented.
  • 503 — Service unavailable.
Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu