> ## Documentation Index
> Fetch the complete documentation index at: https://developers.gonitro.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How the Nitro PDF Services connector authenticates Power Automate flows using OAuth 2.0 client credentials.

Nitro PDF Services uses machine-to-machine **OAuth 2.0 with the client credentials grant**. The
connector handles the whole exchange for you: you supply a Client ID and Client Secret once, per
connection, and every action is authenticated with a bearer token behind the scenes.

## Connection parameters

| Parameter | Type | Required | Notes |
| - | - | - | - |
| **Display name** | Text | No | How the connection appears in the **Connections** list |
| **Nitro Client ID** | Secure string | Yes | Shown in clear text in the connection dialog |
| **Nitro Client Secret** | Secure string | Yes | Masked in the connection dialog and never returned |

Create the Client ID and Secret in the Nitro Developer portal — see
[Credentials](/docs/authentication/credentials).

Connections are **not shareable**. When a flow or Power App is shared, each user creates their own
connection with their own credentials.

## What happens on each call

<Steps>
  <Step title="Your credentials are attached">
    Request policies inside the connector add the connection's Client ID and Client Secret to the
    outgoing request as headers.
  </Step>

  <Step title="They are exchanged for a token">
    The connector's script reads those headers, removes them, and calls
    `POST https://api.gonitro.dev/oauth/token` with `grant_type=client_credentials`.
  </Step>

  <Step title="The token is cached">
    Access tokens are valid for 24 hours. The connector caches each one, keyed on the credentials,
    and reuses it until shortly before expiry. Renewal is automatic — flows never see a token
    expire.
  </Step>

  <Step title="The request is forwarded">
    The script sets `Authorization: Bearer <token>` and sends the request on to the Nitro API.
    Your secret is only ever sent to the token endpoint, never to the operation endpoints.
  </Step>
</Steps>

## Rotating credentials

Rotating a Client Secret in the Nitro Developer portal does **not** update existing Power Automate
connections. After rotating:

1. Open **Connections** in Power Automate.
2. Find the Nitro PDF Services connection, open its **⋯** menu, and choose **Edit** to enter the new
   secret — or delete it and create a new one.
3. If you created a new connection, open each flow that used the old one and re-select the
   connection on every Nitro step (**⋯ → My connections**).

See [Credential rotation](/docs/authentication/credential-rotation) for the Nitro-side process.

<Tip>
  If you keep more than one Nitro connection — for example one per environment or team — give each a
  **Display name** so the right one is obvious in the designer.
</Tip>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Every action returns 401 Unauthorized">
    Nitro rejected the credentials. Re-check the Client ID and Secret on the connection — a trailing
    space pasted into either field is enough to fail the token exchange — and confirm the API
    application still exists in the Nitro Developer portal and its secret has not been rotated.
  </Accordion>

  <Accordion title="Token error (HTTP 401) in the action's error message">
    The connector surfaces token endpoint failures verbatim, prefixed with `Token error`. This
    means Nitro rejected the credentials themselves rather than the operation — the application
    may have been deleted or its secret rotated.
  </Accordion>

  <Accordion title="A flow that used to work now fails on one step">
    Check which connection that step uses. A flow edited in a browser tab that was open before a
    connection was replaced can be saved with the old connection reference. Open the step's
    **⋯ → My connections** and pick the current connection.
  </Accordion>

  <Accordion title="The connection tests fine but a specific action fails">
    Authentication is shared across all actions, so a single failing action points at the request
    rather than the credentials. Check
    [Limits and errors](/docs/integrations/power-automate/limits-and-errors).
  </Accordion>
</AccordionGroup>
