(Replace this first paragraph with a brief description of your new category. This guidance will appear in the category selection area, so try to keep it below 200 characters.)
Use the following paragraphs for a longer description, or to establish category guidelines or rules:
Why should people use this category? What is it for?
How exactly is this different than the other categories we already have?
What should topics in this category generally contain?
Do we need this category? Can we merge with another category, or subcategory?
You’ll get a 401 error when the OAuth Scope isn’t mapped in the Client Credentials. API Endpoint checks fail silently if the Payload is malformed. Token expires in 3600 seconds.
EmbeddableClientAppSdk manages token rotation automatically, so running a raw curl command like that will eventually break your session. First, the client_credentials grant type returns a -level token that completely bypasses user context. Next, when your custom desktop app tries to hit /api/v2/users/me with that payload, the platform returns a 403 because the scope lacks view:user. You need to bind the token to an actual agent identity. The SDK initializes this with platformClient.OAuthApi.loginWithClientCredentials(). Check the payload structure before you send it. If you ignore the refresh cycle, the desktop client will freeze during screen pop routing. Here is how the proper initialization looks:
The token cache sits in localStorage by default. You’ll need to override it for desktop environments. Pretty standard behavior, but it catches people off guard. Network traces show the 401 spikes right after the first API call.