To access the NewsMAN API using OAuth 2.0 authentication, follow these steps:
Registering the application that will use the API with OAuth 2.0 authentication
Use the contact form to send us the following details:
- Application name
redirect_uri: the callback URL where NewsMAN will send a callback (e.g.https://mysite.com/callback)
We will then provide you with two parameters to use for authentication:
client_id(e.g.app_client_example)client_secret(e.g.123123123123)
Authentication
The NewsMAN API uses the OAuth 2.0 protocol for authentication.
All API requests must be made over SSL (https://, not http://).
To authenticate, you will need:
client_id(sent to you after your application is registered)client_secret(sent to you after your application is registered)- Authorization endpoint:
https://ssl.newsman.ro/admin/oauth/authorize - Token endpoint:
https://ssl.newsman.ro/admin/oauth/token
Step 1: Redirect the user to the authorization URL
https://ssl.newsman.ro/admin/oauth/authorize?scope=api&redirect_uri=https%3A%2F%2Fmysite.com%2Fcallback&response_type=code&client_id=app_client_example
If the user is not logged in to NewsMAN, they will be redirected to the login form. The user will then be asked whether they allow the application to access their NewsMAN account.
Step 2: NewsMAN redirects to the callback URL
https://mysite.com/callback?code=jksasda4sda5ssd1a1122sdassdas123
If the user did not grant access to their NewsMAN account, they will be redirected to:
https://mysite.com/callback?error=access_denied&error_description=end-user+denied+authorization
Step 3: Obtain the access_token
In the previous step you received a code, which must be exchanged for an access_token (API key).
To exchange it, send a POST request to the token endpoint https://ssl.newsman.ro/admin/oauth/token with the following parameters:
- code=d869078edb8658f7ccaae5545d506662
- redirect_uri=https%3A%2F%2Fmysite.com%2Fcallback
- client_id=app_client_example
- client_secret=123123123123
- grant_type=authorization_code
If there are no errors, you will receive a JSON response like this:
{
"user_id": 2312121,
"access_token": "6c595cd6db27b05dya3be2f65e28291f",
"expires_in": 1709550943,
"lists": [1, 2],
"token_type": "bearer",
"scope": "api"
}
Use the access_token you obtained (referred to as the API key), together with the user_id, every time you call the API.

