The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Generating an API access token

Prev Next

If the IAM domain you use to access the Trellix UI ends in trellix.com, follow the steps to generate an API access token.

  1. Obtain client credentials. See "Managing client credentials" in the Trellix IAM Guide.

    Make note of the following parameters:

    • Token endpoint: The request will be sent to this token generation endpoint.

    • Client ID: The client ID associated with your application.

    • client secret: The client secret associated with your application.

    • grant_type: The value should be set to "client_credentials" to indicate the type of grant.

    • scope: The scopes or permissions that you want the token to have. These are the subset of the entitlements selected during client ID/secret generation. You can add or remove the scopes as per your requirement.

  2. Generate the access token by making a POST request to the token generation endpoint (`https://auth.trellix.com/auth/realms/IAM/protocol/openid-connect/token`) with the required parameters in the request body.

    cURL code example:

    curl --location 'https://auth.trellix.com/auth/realms/IAM/protocol/openid-connect/token' \
    --header 'Content-Type: application/x-www-form-urlencoded' \
    --user '<Client ID>:<Secret>' \
    --data-urlencode 'grant_type=client_credentials' \
    --data-urlencode 'scope=etp.conf.ro etp.trce.rw etp.admn.ro etp.domn.ro etp.accs.rw
    etp.quar.rw etp.domn.rw etp.rprt.rw etp.accs.ro etp.quar.ro etp.alrt.rw
    etp.rprt.ro etp.conf.rw etp.trce.ro etp.alrt.ro etp.admn.rw'

    The cURL request has the following options:

    • --location: Redirect location.

    • --header 'Content-Type: application/x-www-form-urlencoded': Indicates that the body of the request is URL-encoded.

    • --user '<Client ID>:<Secret>': Use the client ID and secret you obtained from your Trellix IAM account.

    • --data-urlencode 'grant_type=client_credentials': This URL assigns the parameter, grant_type, with the value client_credentials.

    • --data-urlencode 'scope=': This URL assigns the parameter, scope, with a list of scopes. You can add or remove the scopes as per your requirement.

    The response includes the generated token in the access_token field.

    {
    "access_token" : "<access token>" ,
    "expires_in" : 600 ,
    "refresh_expires_in" : 0 ,
    "token_type" : "Bearer" ,
    "not-before-policy" : 0 ,
    "scope" : "etp.conf.ro etp.trce.rw etp.admn.ro etp.domn.ro etp.accs.rw
    etp.quar.rw etp.domn.rw etp.rprt.rw etp.accs.ro etp.quar.ro etp.alrt.rw
    etp.rprt.ro etp.conf.rw etp.trce.ro etp.alrt.ro etp.admn.rw"
    }
  3. Before you can successfully request data for specific domains, you must map the credentials to those domains within the ETP portal:

    1. Log into the Email Security - Cloud web UI.

    2. Go to Administrator > Client Credentials.

    3. Locate your client credential and specify which domains it is allowed to access.

  4. Request for the required ETP URI with the access token included in the request header.

    curl --location --request POST 'ETP_URI' \
    --header 'Authorization: Bearer <access token>'