ejento.ai API
Stable
  • Stable
  • V2
  • V2 Legacy
Stable
  • Stable
  • V2
  • V2 Legacy
ejento.ai
Stable
  • Stable
  • V2
  • V2 Legacy
  1. Integrations
  • Overview
  • Changelog
  • Versioning
  • Quick-Start Template for Building an App
  • FAQs
  • Guides
    • Getting Started
      • How to generate API Key and Auth Token
      • Build an App with Ejento APIs
      • How to Import Ejento APIs into Postman
      • Authentication with Azure AD Token
      • Permission Sets
      • Obtaining the AD App-Only Token
    • Migrations
      • Response API Migration
      • Indexing API Migration
    • Integrations
      • Voice Call API Integration Guide
      • Staging & Publishing for Agents API Guide
      • Chat Thread Attachment Integration Guide
      • App-Only Token Login — Integration Guide
  • Authentication
    • Getting Started with Authentication
    • Authentication and Token Refresh Guide
    • SSO
      • Initiate Google SSO Login
      • Initiate Microsoft SSO Login
      • Initiate LinkedIn SSO Login
      • Initiate Okta SSO Login
      • Exchange Azure AD Token for Ejento Tokens
      • Exchange an Azure AD App-Only Token for Ejento Tokens
      • Initiate Microsoft CIAM SSO Login (Azure AD B2C or Entra External ID)
    • Feature Flags
      • Get Login Feature Flags
    • Authenticate User
    • Request Passwordless Exchange Token
    • Exchange Passwordless Token for Access Tokens
    • Register User
    • Refresh Access Token
    • Update Own Password
    • Validate Magic Link Token
    • Passwordless Authentication (Email Magic Link)
    • Verify Email OTP
    • Request Password Recovery Email
    • Reset Password
  • Agents
    • Agent Access
      • Get Agent Access
      • Update Agent Access
    • Agent Alias
      • Get Agent Alias
      • Create an Agent Alias
      • Update an Agent Alias
      • Delete an Agent Alias
      • Get all Agent Aliases
    • Agent Tags
      • Add or Remove Tags from an Agent
      • Get all Tags for a given Project or Organization
      • Get all Tags grouped by Agent for a given Project or Organization
    • Agent Chat Threads
      • Get Chat Threads of an Agent
      • Create Chat Thread for an Agent
    • Agent Comment
      • Get all Comments for an Agent
      • Create a Comment
      • Update a Comment
      • Delete a Comment
    • Agent Rating
      • Get Ratings of an Agent
      • Update Agent Rating
      • Get all Agent Ratings
    • Agent Review
      • Get all Reviews for specific Agent
      • Create a new Review
      • Get all Reviews of the Authenticated User
      • Update a Review
      • Delete a Review
    • Agent Tools
      • List all Tools with their enabled status for the given Agent
      • Unlink an Agent from a Tool
      • Link an Agent to a Tool
      • List all tools that are connected to the Agent
    • Agent Vote
      • Get Vote Information for an Agent
      • Vote on an Agent
    • Agent Type
      • Get all Agent Types
      • Get a specific Agent Type
      • Update a specific Agent Type
    • Evaluation Datasets
      • List Agent Evaluation Datasets
      • Create Agent Evaluation Dataset
      • Batch Delete Agent Evaluation Datasets
      • Get Agent Evaluation Dataset
      • Update Agent Evaluation Dataset
      • Delete Agent Evaluation Dataset
      • Upload Agent Evaluation Dataset (CSV/Excel)
    • Evaluation Runs
      • List Agent Evaluation Runs
      • Create Agent Evaluation Run
      • Batch Delete Agent Evaluation Runs
      • Get Agent Evaluation Run
      • Update Agent Evaluation Run
      • Delete Agent Evaluation Run
    • Agent Permissions
      • List all permissions on an agent
      • Grant permission on an agent
      • Update a permission on an agent
      • Revoke permission on an agent
      • Grant multiple permissions on an agent
      • Revoke multiple permissions on an agent
      • Get user permissions on a specific agent
      • Get user permissions on multiple agents
    • Agent Skills
      • Get all Skills available to an Agent
      • Unlink a Skill from an Agent
      • Link a Skill to an Agent
    • Get all Agents
    • Create a new Agent
    • Get an Agent
    • Update an Agent
    • Delete an Agent
    • Activate an Agent
    • Get Agent-Corpus Connections
    • Create Multiple Agent-Corpus Connections
    • Delete Agent-Corpus Connections
    • Get Agent-Corpus Connection Details
    • Create Agent-Corpus Connection
    • Update Agent-Corpus Connection
    • Delete Agent-Corpus Connection
    • Get agent history with pagination
    • Restore an agent to a previous checkpoint
    • Get a single agent history record by history ID
    • Create Custom Instructions for an Agent
    • Update Custom Instructions for an Agent
    • Delete a Custom Instruction for an Agent
    • Get Agent Prompt History
    • Create a Recent Agent
    • Delete a Recent Agent
    • Get Agent Details with Starred Status
    • Create Starred Agent
    • Delete Starred Agent
    • Get the Status of an Agent
    • Get all Character Voices
    • Get Agent Filter
    • Generate an image for an agent based on the provided description
    • Get all Agents by Project
    • Get list of Recent Agents
    • Get all workflows for an agent
    • Get all Starred Agents of the Authenticated User
    • Get Staging Diff
    • Get publish history for an agent
    • Get rollback diff preview for a publish record
    • Roll back staging agent to a previous publish
    • Publish staging agent to main
    • Clone an Agent
    • Get diff detail for a publish record
  • Agent Response
    • Stream Agent Response (SSE)
    • Generate Agent Response (Non-Streaming)
    • Generate Token for Voice Call
    • Get an Agent Response
    • Update an Agent Response
    • Delete an Agent Response
    • Get Comments for Agent Response
    • Create a Comment for Agent Response
    • Create a Feedback for an Agent Response
    • Pin an Agent Response
    • Unpin an Agent Response
    • Get Supporting Content of an Agent Response
    • Get Thoughts of an Agent Response
    • Get Agent Responses based on filters
    • Get Agent Responses of an Agent
    • Create Agent Response Log
    • Get Pinned Agent Responses
    • Create Bulk Agent Response Logs
    • Stop an in-flight streaming response
  • Chat Thread
    • Agent Response
      • Get Agent Responses for a Chat Thread
      • Delete Agent Responses for a Chat Thread
    • Chat Logs
      • Get Chat Logs for a Chat Thread
    • Corpus Connection
      • Get Corpus Connection by ChatThread ID
      • Delete Corpus Connection by ChatThread ID
      • Get a ChatThread-Corpus connection
      • Create a ChatThread-Corpus connection
      • Delete a ChatThread-Corpus connection
    • Documents
      • Get Documents in Chat Thread
    • Thread Share
      • List Thread Shares
      • Create Thread Share
      • Update Thread Share
      • Get Thread Share Settings
      • Refresh Thread Share Snapshot
      • View Thread Share
      • Get Thread Share Access Log
      • Revoke Thread Share
    • Get Chat Thread
    • Update Chat Thread
    • Delete Chat Thread
    • Get Chat Threads based on various filters
    • Global Hybrid Search across Chat Threads and Chatlogs
    • Get Recent Chat Threads across all Agents
  • Chat Logs
    • Get Chat Log Details
    • Get Chat Log Search Results
  • Conversation Starters
    • Get Conversation Starters for an Agent
    • Create a new Conversation Starter.
  • Teams
    • Team Permissions
      • List all permissions on a team
      • Grant permission on a team
      • Update a permission on a team
      • Revoke permission on a team
      • Grant multiple permissions on a team
      • Revoke multiple permissions on a team
      • Get user permissions on a specific team
      • Get user permissions on multiple teams
    • Get all Teams
    • Create a Team
    • Get a Team
    • Update a Team
    • Delete a Team
    • Get all Projects of a Team
    • Create a Recent Team
    • Get all Users in a Team
    • Add Users to a Team
    • Remove User from Team
    • Get Recent Teams
    • Get all Teams of the Authenticated User
  • Projects
    • Project Permissions
      • List all permissions on a project
      • Grant permission on a project
      • Update a permission on a project
      • Revoke permission on a project
      • Grant multiple permissions on a project
      • Revoke multiple permissions on a project
      • Get user permissions on a specific project
      • Get user permissions on multiple projects
    • Retrieve all Projects
    • Create a Project
    • Get a Project
    • Update a Project
    • Delete a Project
    • Get Agent Responses using Project ID
    • Add a Recent Project for a User
    • Add Users to a Project
    • Remove a User from a Project
    • Get all Workflows for a Project
    • Get multiple Projects by their IDs
    • Get Projects based on filters
    • Get Recent Projects for a User
    • Get Projects with Team Details
  • Corpora
    • Corpus Permissions
      • Get all Permissions for a Corpus
      • Grant permission on a corpus
      • Update a permission on a corpus
      • Revoke permission on a corpus
      • Batch grant permissions on a corpus
      • Batch revoke permissions on a corpus
      • Get calling user's permissions on a corpus
      • Get a user's permissions on a corpus
      • Get a user's permissions across multiple corpora
    • Get all Corpus
    • Upload a Document to a Corpus
    • Create a Corpus
    • Get a Corpus
    • Update a Corpus
    • Delete a Corpus
    • Get Corpus Agent Connections
    • Get Default Corpus Agent Connection
    • Annotate/Tag a Corpus
    • Get Conversation Starters for a Corpus
    • Get all Documents for a Corpus
    • Delete Document(s) from a Corpus
    • Check Duplicate Documents in a Corpus
    • Trigger a Refresh (Reindex) of a Corpus
    • Get Sitemaps for a Corpus
    • Get Corpora with Refresh (Reindex) Enabled
  • Documents
    • Get a Document
    • Update a Document
    • Delete a Document
    • Annotate a Document
    • Get Conversation Starters for a Document
    • Trigger a Refresh (Reindex) of a Document
    • Retrieve multiple Documents by IDs
  • Organizations
    • Organization Permissions
      • List all permissions on an organization
      • Get user permissions on a specific organization
      • Get My Organization Permissions
    • Get all Configurations
    • Get active configuration for an Organization
    • Get the Model Deployment for an Organization
    • Get all Tools in an Organization
    • Disable a Tool for all Agents in an Organization
    • Enable a Tool for all Agents in an Organization
    • Get all API Tool Templates
    • Create a new API Tool Template
    • Create a new API tool
    • Create an attachment tool
    • Create a new RAG tool in an Organization
    • Create a Web Search Tool in an Organization
    • Get all Users in an Organization
    • Create a User in an Organization
    • Get all Configurations of user's Organization
    • Register LLM Configuration
    • Update LLM Configuration
    • Toggle LLM Configuration Availability
    • Delete LLM Configuration
    • Get a specific LLM configuration by ID (admin only)
  • Users
    • Get a User
    • Update a User
    • Delete a User
    • Get Agent Responses of a User
    • Assign a user to multiple permission sets
    • Get all User Permissions
    • Preview a user's permissions after assigning/removing permission sets
    • Get Projects of a User
    • Get all Workflow Tables for a User
    • Get all Workflows for a User
    • Delete multiple Users
    • Get a specific User by user_email
    • Get all Users
    • Get authenticated User
    • Get User Projects
  • Analytics
    • Get Agent Cost Data
    • Get Agent Document Count Data
    • Get Agent Indexing Mode Data
    • Get Agent Most Active Data
    • Get Agent Query Count Data
    • Get Recent Agent Data
    • Get Agent Summary Statistics
    • Get Agent Token Data
    • Get Agent Vote Data
    • Get Corpus Document Count Data
    • Get Corpus Indexing Mode Data
    • Get Cost Data
    • Get Document Count Data
    • Get Indexing Mode Data
    • Get Project Cost Data
    • Get Project Document Count Data
    • Get Project Indexing Mode Data
    • Get Project Most Active Data
    • Get Project Query Count Data
    • Get Recent Project Data
    • Get Project Summary Statistics
    • Get Project Token Data
    • Get Project Vote Data
    • Get Overall Summary Statistics
    • Get Team Cost Data
    • Get Team Document Count Data
    • Get Team Indexing Mode Data
    • Get Team Most Active Data
    • Get Team Query Count Data
    • Get Recent Team Data
    • Get Team Summary Statistics
    • Get Team Token Data
    • Get Team Vote Data
    • Get Total Entity Counts
    • Get User Cost Data
    • Get User Document Count Data
    • Get User Indexing Mode Data
    • Get User Most Active Data
    • Get User Query Count Data
    • Get Recent User Data
    • Get User Summary Statistics
    • Get User Token Data
    • Get User Vote Data
    • Get Vote Count Data
    • Get Workflow Summary Statistics
    • Get Query Count Data
    • Get Token Data
  • Configurations
    • Update the LLM configuration for an Agent
    • Get OAuth-related Feature Flags
  • Guardrails
    • Apply Guardrails on Input Text
    • Get available guardrail types for agent
    • Enable/disable a guardrail type for agent
    • Get Guardrails
    • Update Guardrails
    • Delete Guardrails
    • Get Guardrails in Organization
    • Create Guardrail in Organization
    • Enable or Disable Guardrail for Organization
  • Feature Flags
    • Get All Feature Flags
    • Get Agent Alias Feature Flag
    • Get Agent Evaluation Feature Flag
    • Get Api Tools Feature Flag
    • Get Caching Feature Flag
    • Get Call Feature Flag
    • Get Chat Agent Creation Feature Flag
    • Get Chat Widget Feature Flag
    • Get dall_e Image Generation Feature Flag
    • Get Developer Portal Feature Flag
    • Get Flush Cache Feature Flag
    • Get Google Drive Connector Feature Flag
    • Get Guardrail Feature Flag
    • Permission Sets Feature Flag
    • Get PII Redaction Feature Flag
    • Get Share Agent Feature Flag
    • Get Sharepoint Legacy Feature Flag
    • Show Quota Limit Feature Flag
    • Get Skills Feature Flag
    • Get Staging Agent Feature Flag
    • Get Workflow Evaluation Feature Flag
    • Get Youtube Index Feature Flag
  • Notifications
    • Get all Notifications
    • Create a new Notification
    • Update Notifications by User ID
    • Get a Notification
    • Update a Notification
    • Delete a Notification
  • Tools
    • Get Tool by ID
    • Update Tool by ID
    • Delete Tool by ID
  • Workflows
    • Evaluation Datasets
      • List Workflow Evaluation Datasets
      • Create Workflow Evaluation Dataset
      • Batch Delete Workflow Evaluation Datasets
      • Get Workflow Evaluation Dataset
      • Update Workflow Evaluation Dataset
      • Delete Workflow Evaluation Dataset
      • Upload Workflow Evaluation Dataset (CSV/Excel)
    • Evaluation Runs
      • List Workflow Evaluation Runs
      • Create Workflow Evaluation Run
      • Batch Delete Workflow Evaluation Runs
      • Get Workflow Evaluation Run
      • Update Workflow Evaluation Run
      • Delete Workflow Evaluation Run
    • Workflow Permissions
      • Get all Permissions for a Workflow
      • Grant permission on a Workflow
      • Update a permission on a Workflow
      • Revoke permission on a Workflow
      • Batch grant permissions on a Workflow
      • Batch revoke permissions on a Workflow
      • Get a user's permissions on a workflow
      • Get a user's permissions across multiple workflows
    • Get all Workflows
    • Stream Workflow Response (SSE)
    • Create a Workflow
    • Get a Workflow
    • Update a Workflow
    • Delete a Workflow
    • Get all Workflow Chat Threads
    • Create a Workflow Chat Thread
    • Get all Workflow Responses
    • Create a Workflow Chat Response
    • Get a Workflow Chat Thread
    • Update a Workflow Chat Thread
    • Delete a Workflow Chat Thread
    • Get all Workflow Chat Responses
    • Delete a Workflow Response
    • Create a Workflow Feedback
    • Retrieve a list of reviews for a given workflow response
    • Create a Workflow Review
    • Get Workflow Responses based on filters
  • Citation
    • Get Citation File Content
  • Sitemaps
    • Get a Sitemap
    • Toggle Sitemap Syncing
    • Delete a Sitemap (cascade)
    • Get documents linked to a Sitemap
  • Google Drive
    • Folder Mappings
      • Get Google Drive Folder Mappings by Corpus ID
  • Skills
    • List all Skills in an Organization
    • Create a new Skill
    • Retrieve a Skill in an Organization
    • Update a Skill
    • Disable a Skill for all Agents in an Organization
    • Update Skill Metadata
    • Enable a Skill for all Agents in an Organization
    • Delete a Skill
    • Get a Skill with Content
    • Get a File from a Skill
  • Permission Sets
    • List org permission sets
    • Create a permission set
    • Retrieve a permission set
    • Update a permission set
    • Delete a permission set
    • List permission set members
    • Assign one or more members to a permission set
    • Remove one or more members from a permission set
  • Usage
    • Get Spend Limits
    • Set Org Spend Limit
    • Set Default User Spend Limit
    • Set Per-User Spend Limit Override
    • Remove Per-User Spend Limit Override
    • Get Per-User Spend Limit Override
    • Get Governance Settings
    • Update Governance Settings
    • Request Spend Limit Increase
    • List Spend Limit Increase Requests
    • Approve Spend Limit Increase Request
    • Deny Spend Limit Increase Request
    • Get Spend Overview
    • Get Spend Trends Summary
    • Get Daily Spend Trend
    • Get Spend By Model
    • Get Spend By Assistant
    • Get Spend Users Table
    • Get Spend User Detail
    • Get My Spend
  1. Integrations

App-Only Token Login — Integration Guide

For services that call Ejento AI with no user present, such as a scheduled job, a timer-triggered function or a background worker. Your service signs in as itself, so there is no browser, no interactive sign-in and no MFA prompt.
This guide assumes your service can already get an app-only token from Microsoft Entra. If it cannot yet, start with Getting an App-Only Token.

How it works#

Your service exchanges its app-only token with Ejento AI for an Ejento AI access token. Ejento AI never sees your client secret. It trusts the token because Microsoft signed it, and it decides who the caller is from the application ID inside the token. You register which applications may do this, and which Ejento AI account each one acts as, in Service Clients.
 Your service                    Microsoft Entra                 Ejento AI
 ────────────                    ───────────────                 ─────────
 1. Request a token  ─────────►  issues an app-only token
 2. Send that token  ──────────────────────────────────────────► checks the token, and checks
                                                                 your app is registered in
                                                                 Service Clients
 3. Receive          ◄────────────────────────────────────────── an Ejento AI access token
 4. Call Ejento AI APIs with the Ejento AI access token
Step 1 is covered in Getting an App-Only Token. This guide covers steps 2 to 4.

Before you start#

You need:
An application in Microsoft Entra that your service uses to get its token. If you don't have one yet, see Getting an App-Only Token.
That application's Application (client) ID and Directory (tenant) ID. You enter them when you register the application in Ejento AI.
A Global Admin in Ejento AI to do the registration.
A new email address for the service account. Ejento AI creates it when the Global Admin creates the Service Client (section 1).
#StepWho
1Register the application in Ejento AI under Service ClientsYour Global Admin
2Exchange the app-only token with Ejento AIYour service, at runtime
3Call Ejento AI APIs with the Ejento AI access tokenYour service

1. Register your application in Ejento AI#

A Global Admin registers the application in Ejento AI. This links it to an Ejento AI account, the service account, that the application acts as. Everything the application does in Ejento AI is done as that account, with its organization and team access. Ejento AI creates the account when you register the application as the Service Client.
Until the application is registered, every exchange is refused with Calling application is not authorized.

Choose the service account email first#

Pick a new address for this integration only, for example [email protected].
The address is only for this integration. Once registered, it cannot be used to sign in to Ejento AI as a person, with a password, a magic link or Microsoft sign-in. Revoking the client does not change that.
One application, one account. An application can act as only one account. To use a different account, register a different application.

Adding a service client (steps a Global Admin needs to perform)#

1.
Go to "Organization Settings".
2.
Select "Service Clients" in the left sidebar.
2.png
3.
Add details for the service client.
3.png
FieldRequiredWhat to enter
NameYesA label you will recognise later, e.g. Transcript Service.
Application (Client) IDYesYour application's Application (client) ID.
Tenant IDNo, but recommendedYour application's Directory (tenant) ID. When set, tokens from any other tenant are refused. Ejento AI checks with Microsoft that the tenant exists.
Service account emailYesThe new address chosen above.
The Application ID, Tenant ID and service account email cannot be changed after the client is created. To change any of them, create a new client and revoke the old one.
4.
Click "Create Client". The new service client appears in the Service Clients table.
4.png

Errors when registering#

MessageWhat to do
'<email>' is an existing user. Use a dedicated service address.Choose an address that is not already an Ejento AI user.
'<value>' is not a valid Directory (tenant) ID. Expected a GUID, as shown on the app registration's Overview page.Copy the Directory (tenant) ID from the app's Overview page in Entra.
Tenant '<id>' was not found in Microsoft Entra. Check the Directory (tenant) ID on the app registration.The ID is well formed but no such tenant exists. Check for a typo.
This app_id is already registered with service_email '<email>'. One app_id maps to exactly one service account.The application already acts as another account. Use that account, or a different application.
This app_id is already registered with a different tenant_id. ...Use the same Tenant ID as the existing registration for that application.
A service client with this app_id and service_email is already registered in this organizationIt is already registered. Edit or restore the existing one.

Checking that it works#

The newly created service account should now appear in the Users table.
image.png

Revoking and restoring a client#

Revoking a client blocks the application immediately, with no deployment needed. The application keeps getting tokens from Microsoft as normal, so a revoked integration fails at the Ejento AI exchange with 403 Calling application is not authorized. A revoked client can be restored. Clients cannot be deleted.
image.png

2. Exchange the token with Ejento AI#

There is no Authorization header, because the token in the body is the credential. No email is sent. Ejento AI identifies your application from the token and looks up the account you registered for it in section 1.
Success, 200:
{
  "success": true,
  "message": "Login successful",
  "data": {
    "access_token": "eyxxxxxx...",
    "ejento_access_token": "aaaaaaaa-bbbbbb-cccc-ddddd-eeeeeee",
    "token_type": "bearer"
  }
}

Calling Ejento AI APIs#

Use ejento_access_token to call the Ejento AI APIs, sent as Authorization: Bearer <ejento_access_token>. The access_token is for the Ejento AI auth service itself, for example the refresh call below. The Ejento AI APIs do not accept it.

Token lifetime and refresh#

Both tokens are time-limited. The access_token expires 7 days after it is issued, so refresh before then, at least once every 6 days:
There is no request body. The response has the same shape as the exchange above, with a new access_token and ejento_access_token. Replace both stored values. Full details are in Authentication and token refresh.
Because your service can always get a new token from Microsoft, it can also repeat the exchange instead of refreshing.

3. What Ejento AI checks#

All of these must hold or the exchange is refused:
CheckRequirement
SignatureSigned by Microsoft. Verified against Microsoft's public keys, so it cannot be forged.
Issuer (iss)A Microsoft Entra tenant. v1 and v2 tokens are both accepted.
App-onlyNo scp claim. A token from a user sign-in is refused.
Application (appid / azp)Matches an active client in Service Clients.
Tenant (tid)Matches the client's Tenant ID, if one is set.
Audience (aud)Matches the audience your token was requested for.
Both spellings of the audience, api://<guid> and the bare <guid>, are accepted, so the token version does not matter.

4. Error reference#

All errors share one format:
{"success": false, "message": "Request Failed",
 "data": {"error": {"code": "HTTP_401", "details": "<message>"}}}
A 401 is about the token. A 403 means the token was valid but the caller is not allowed.
A 503 means Microsoft could not be reached. It is never a bad token.
StatusMessageMeaningWhat to do
401Invalid Azure AD token: Audience doesn't matchThe token was requested for a different audienceRequest the token for the audience in Which token to request
401Invalid Azure AD token: ...Bad signature, malformed token or unknown signing keyCheck you are sending the token exactly as Microsoft returned it
401Azure AD token has expiredThe token is past its expiryRequest a new token
401Token issuer is not a valid Microsoft tenantThe token was not issued by Microsoft EntraRequest it from login.microsoftonline.com
401Expected an app-only token, but a delegated user token was providedThe token came from a user sign-inUse the app-only flow in Getting an App-Only Token
401Token does not identify a calling applicationThe token has no application IDUse the app-only flow in Getting an App-Only Token
401Token tenant does not match the registered clientThe token's tenant differs from the client's Tenant IDCheck the Tenant ID on the client
403Calling application is not authorizedNo active client for this applicationCheck the client exists, is active, and its Application ID matches your app
403Service user does not exist. Register the service client first.The account behind the client could not be foundContact Ejento AI
403App-only token login is currently disabledThis sign-in method is off for your deploymentContact Ejento AI
503Could not reach Microsoft to verify the token signatureMicrosoft is temporarily unreachableRetry with backoff
Troubleshooting a 401: decode your token and compare it with Check the token in Getting an App-Only Token. If you need help from Ejento AI, send the decoded claims. Do not send the token itself. It is a working credential until it expires.

5. Operational notes#

Revocation. If a working integration suddenly gets a 403, check whether the client was revoked in Service Clients before debugging tokens.
Secret expiry. An expired client secret fails at Microsoft, before the request reaches Ejento AI. See Keep the secret current in Getting an App-Only Token.
Previous
Chat Thread Attachment Integration Guide
Next
Authentication
Built with