Authorization header. You can authenticate with a short-lived token — valid for 24 hours and obtained by exchanging your email and password — or with a long-lived API key generated from your account dashboard. Both credential types are passed identically as Bearer tokens once issued.
POST /auth/token
Exchange your account email and password for a Bearer token. This endpoint expects a form-encoded request body.POST /auth/token
Request
The request body must be encoded asapplication/x-www-form-urlencoded.
string
required
Your Nexenergie account email address (e.g.,
user@example.com).string
required
The password associated with your Nexenergie account.
Response
A successful200 OK response returns the following JSON body:
string
The Bearer token to include in the
Authorization header of all subsequent API requests.string
Always
"bearer". Indicates how the token should be presented in the header.integer
Lifetime of the token in seconds. The default value is
86400 (24 hours), after which the token is no longer valid and a new one must be requested.Example Response
Authorization Header
Once you have a token, pass it in theAuthorization header on every subsequent request:
API Keys
API keys are long-lived credentials that you generate directly from your Nexenergie account dashboard under API Keys settings. They are suitable for server-side integrations, automated pipelines, and any context where re-authenticating with a username and password would be impractical. API keys are used identically to short-lived tokens — pass them as the Bearer value in theAuthorization header:
POST /auth/token, API keys do not expire based on time. They remain valid until you explicitly revoke them from the dashboard. You can create multiple keys with descriptive labels to identify which integration each key belongs to, and rotate or revoke them individually without affecting other keys.
Token Expiry
Tokens issued byPOST /auth/token expire after 86400 seconds (24 hours). Requests made with an expired token return 401 Unauthorized. Your integration should detect expiry and re-authenticate before continuing.
The following Python example shows a simple retry-with-refresh pattern:
Python