OAuth 2.0 machine-to-machine (M2M) authentication

Added

  • Machine-to-machine (M2M) authentication — New guide for authenticating server-to-server calls with the OAuth 2.0 client_credentials grant. Create an M2M app with the Brevo CLI, exchange its client_id and client_secret at https://oauth.brevo.com/realms/partner/oauth/token for a short-lived access token (about 1 hour, no refresh token), then call the API with Authorization: Bearer <token> instead of the api-key header. API keys are unaffected and keep working.
  • API reference authentication — The API reference now lists OAuth 2.0 alongside API key as an authentication option. See Authentication schemes.
  • CLI reference — Documented the M2M commands: brevo app create --m2m --scopes, brevo app list --type m2m, brevo app token, brevo app secret rotate, and brevo app scopes update. These commands require a Brevo CLI release that includes Machine-to-machine support.

Improved

  • OAuth 2.0 — The page now explains the two OAuth flows, machine-to-machine and OAuth apps (user consent), when to use each, and how they compare with API keys.
  • Authentication schemes and API key authentication — The OAuth 2.0 option now covers both flows, and API key authentication points new server-to-server integrations to M2M.

Request an explicit scope when you get a token. A token requested without one is currently issued with all of the app’s scopes.