Skip to main content
All Nexenergie API requests must include a valid credential in the Authorization header. You can authenticate with a short-lived token — valid for 24 hours and obtained by exchanging your email and password — or with a long-lived API key generated from your account dashboard. Both credential types are passed identically as Bearer tokens once issued.

POST /auth/token

Exchange your account email and password for a Bearer token. This endpoint expects a form-encoded request body. POST /auth/token

Request

The request body must be encoded as application/x-www-form-urlencoded.
string
required
Your Nexenergie account email address (e.g., user@example.com).
string
required
The password associated with your Nexenergie account.

Response

A successful 200 OK response returns the following JSON body:
string
The Bearer token to include in the Authorization header of all subsequent API requests.
string
Always "bearer". Indicates how the token should be presented in the header.
integer
Lifetime of the token in seconds. The default value is 86400 (24 hours), after which the token is no longer valid and a new one must be requested.
Example Response

Authorization Header

Once you have a token, pass it in the Authorization header on every subsequent request:

API Keys

API keys are long-lived credentials that you generate directly from your Nexenergie account dashboard under API Keys settings. They are suitable for server-side integrations, automated pipelines, and any context where re-authenticating with a username and password would be impractical. API keys are used identically to short-lived tokens — pass them as the Bearer value in the Authorization header:
Unlike tokens obtained from POST /auth/token, API keys do not expire based on time. They remain valid until you explicitly revoke them from the dashboard. You can create multiple keys with descriptive labels to identify which integration each key belongs to, and rotate or revoke them individually without affecting other keys.
Use separate API keys for each environment (development, staging, production) and each integration. This lets you rotate or revoke a single key without disrupting other services.

Token Expiry

Tokens issued by POST /auth/token expire after 86400 seconds (24 hours). Requests made with an expired token return 401 Unauthorized. Your integration should detect expiry and re-authenticate before continuing. The following Python example shows a simple retry-with-refresh pattern:
Python
Never log, print, or embed tokens or API keys in client-side code, version control, or publicly accessible configuration files. Anyone who obtains your credential can make API calls charged against your account and access your organisation’s forecast data. Use environment variables or a secrets manager to store credentials securely.