Connection fields
Create the Client ID and Secret in the Nitro Developer portal — see
Credentials.
What happens on each call
1
Zapier exchanges your credentials for a token
The app calls
POST https://api.gonitro.dev/oauth/token with grant_type=client_credentials
and your Client ID and Secret as HTTP Basic authentication.2
The token is stored on the connection
Zapier keeps the access token as session data and attaches it as
Authorization: Bearer <token> — only on requests to api.gonitro.dev. File downloads from
the URLs your Zap supplies never carry the token.3
Expired tokens are refreshed automatically
If Nitro returns
401, the app raises a refresh, Zapier re-runs the token exchange, and
retries the request. Zaps do not fail because of an expired token.Your Client Secret is only ever sent to the token endpoint. Operation requests carry the bearer
token instead.
Rotating credentials
Rotating a Client Secret in the Nitro Developer portal does not update existing Zapier connections. After rotating, open My Apps in Zapier, find the Nitro PDF Services connection, and choose Reconnect to enter the new secret. Zaps using that connection pick it up immediately. See Credential rotation for the Nitro-side process.Troubleshooting
Connecting fails with 'Nitro rejected the credentials'
Connecting fails with 'Nitro rejected the credentials'
Nitro’s token endpoint refused the Client ID and Secret. Re-copy both from the Developer portal —
a trailing space is enough to fail — and confirm the API application still exists and its
secret has not been rotated. The error includes Nitro’s own reason in brackets when one is
returned.
A Zap that used to work now fails every step with 401
A Zap that used to work now fails every step with 401
The credentials behind the connection are no longer valid — usually a rotated secret or a
deleted application. Reconnect the app in My Apps.
The connection tests fine but one action fails
The connection tests fine but one action fails
Authentication is shared across all actions, so a single failing action points at the request
rather than the credentials. Check
Limits and errors.