Authentication and Authorization

GO1 uses OAuth2 for authentication and authorization purposes. If you are not familiar we recommend An Introduction to OAuth2.

When your application wants to access GO1 API Resources for the first time, these steps take place:

  1. Your application redirects the user to GO1
  2. The user logs into GO1
  3. The user selects which portal to grant access to
  4. The user authorizes your application to access the requested GO1 API Resources
  5. Your application receives a response that will facilitate an access token it can use for API requests.

GO1 Portals

GO1 users belong to one or more portals. This API only supports accessing data from one portal at a time. If you need to retrieve data from multiple portals you will need to authenticate with each portal and separately request the data.

Getting your application credentials

You can can get your credentials by contacting or programmatically.

Generating application credentials

This functionality is not part of the OAuth2 specification but it works by overloading it. It is discouraged, but if you find you need to generate application credentials on demand this is how to do it:

  1. Set your client_id to any value except an already existing client id.
  2. Append new_client=MyClientName to your query string, where MyClientName is how you want to name your client.
  3. When the OAuth flow completes, you'll receive two extra parameters in the query string or fragment:
    • client_id: The newly created client id
    • client_secret: The secret of your new client id
  4. Store your new client id and secret and continue with the standard flow.

Scopes: Requesting the Right Permissions

There is a specific set of access rights your application can request:

  • Read account information
  • Read enrollment data
  • enrollment.write: Modify enrollments
  • Access learning objects data, like courses and collections.
  • lo.write: Modify learning objects
  • Read portal configuration
  • portal.write: Modify portal configuration
  • Read user data
  • user.write: Modify users
  • Read webhook configuration
  • webhook.write: Modify webhook configuration

Your application should know beforehand what operations it needs to do and request the appropriate scopes.
If further down the road you need additional scopes, you'll need to request a new access token.

Trying to access a GO1 API Resource without the right scopes will return a 403 Forbidden HTTP status code.

Authentication and Authorization

Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.