> ## Documentation Index
> Fetch the complete documentation index at: https://developers.gonitro.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How the Nitro PDF Services Zapier app authenticates using OAuth 2.0 client credentials.

Nitro PDF Services uses machine-to-machine **OAuth 2.0 with the client credentials grant**. In
Zapier terms the app uses **session authentication**: you enter a Client ID and Client Secret
once, and Zapier holds a short-lived access token for you.

## Connection fields

| Field | Type | Required | Notes |
| - | - | - | - |
| **Client ID** | Text | Yes | |
| **Client Secret** | Password (masked) | Yes | |
| **Connection Name** | Text | No | Shown in the Zap editor's account picker. Blank → *Nitro app …* plus the last four characters of the Client ID |

Create the Client ID and Secret in the Nitro Developer portal — see
[Credentials](/docs/authentication/credentials).

## What happens on each call

<Steps>
  <Step title="Zapier exchanges your credentials for a token">
    The app calls `POST https://api.gonitro.dev/oauth/token` with `grant_type=client_credentials`
    and your Client ID and Secret as HTTP Basic authentication.
  </Step>

  <Step title="The token is stored on the connection">
    Zapier keeps the access token as session data and attaches it as
    `Authorization: Bearer <token>` — only on requests to `api.gonitro.dev`. File downloads from
    the URLs your Zap supplies never carry the token.
  </Step>

  <Step title="Expired tokens are refreshed automatically">
    If Nitro returns `401`, the app raises a refresh, Zapier re-runs the token exchange, and
    retries the request. Zaps do not fail because of an expired token.
  </Step>
</Steps>

<Note>
  Your Client Secret is only ever sent to the token endpoint. Operation requests carry the bearer
  token instead.
</Note>

## Rotating credentials

Rotating a Client Secret in the Nitro Developer portal does **not** update existing Zapier connections.
After rotating, open **My Apps** in Zapier, find the Nitro PDF Services connection, and choose
**Reconnect** to enter the new secret. Zaps using that connection pick it up immediately.

See [Credential rotation](/docs/authentication/credential-rotation) for the Nitro-side process.

## Troubleshooting

<AccordionGroup>
  <Accordion title="Connecting fails with 'Nitro rejected the credentials'">
    Nitro's token endpoint refused the Client ID and Secret. Re-copy both from the Developer portal —
    a trailing space is enough to fail — and confirm the API application still exists and its
    secret has not been rotated. The error includes Nitro's own reason in brackets when one is
    returned.
  </Accordion>

  <Accordion title="A Zap that used to work now fails every step with 401">
    The credentials behind the connection are no longer valid — usually a rotated secret or a
    deleted application. Reconnect the app in **My Apps**.
  </Accordion>

  <Accordion title="The connection tests fine but one action fails">
    Authentication is shared across all actions, so a single failing action points at the request
    rather than the credentials. Check
    [Limits and errors](/docs/integrations/zapier/limits-and-errors).
  </Accordion>
</AccordionGroup>
