Create an access token
The host domain for OAuth endpoints is login.pinecone.io.
// Requires Node.js SDK v8.2.0 or later
import { AdminClient } from '@pinecone-database/pinecone';
// You don't call this endpoint directly when using the SDK. The AdminClient
// exchanges your service account credentials for an access token on the first
// admin request and reuses it for subsequent calls.
const admin = new AdminClient({
clientId: 'YOUR_CLIENT_ID',
clientSecret: 'YOUR_CLIENT_SECRET',
});
const { data: projects } = await admin.projects.list();
console.log(projects);// Requires Go SDK v6.0.0 or later
package main
import (
"context"
"fmt"
"log"
"github.com/pinecone-io/go-pinecone/v6/pinecone"
)
func main() {
ctx := context.Background()
// You don't call this endpoint directly when using the SDK. The AdminClient
// exchanges your service account credentials for an access token.
adminClient, err := pinecone.NewAdminClientWithContext(ctx, pinecone.NewAdminClientParams{
ClientId: "YOUR_CLIENT_ID",
ClientSecret: "YOUR_CLIENT_SECRET",
})
if err != nil {
log.Fatalf("Failed to create AdminClient: %v", err)
}
projects, err := adminClient.Project.List(ctx)
if err != nil {
log.Fatalf("Failed to list projects: %v", err)
}
fmt.Printf("Found %v projects\n", len(projects))
}curl "https://login.pinecone.io/oauth/token" \ # Note: Base URL is login.pinecone.io
-H "X-Pinecone-Api-Version: 2026-04" \
-H "Content-Type: application/json" \
-d '{
"grant_type": "client_credentials",
"client_id": "YOUR_CLIENT_ID",
"client_secret": "YOUR_CLIENT_SECRET",
"audience": "https://api.pinecone.io/"
}'{
"access_token":"YOUR_ACCESS_TOKEN",
"expires_in":86400,
"token_type":"Bearer"
}POST /oauth/token
Parameters
Section titled “Parameters”X-Pinecone-Api-Version(header, string, required) — Required date-based version header
Request body
Section titled “Request body”client_id(body, string, required) — The service account's client ID.client_secret(body, string, required) — The service account's client secret.grant_type(body, string, required) — The type of grant to use.audience(body, string, required) — The audience for the token.
Responses
Section titled “Responses”200— A response that contains the access token.400— Invalid request.401— Unauthorized.403— Forbidden.429— Too many requests.500— Internal server error.501— Not implemented.503— Service unavailable.