---
updatedAt: 2026-07-24T07:19:53.000Z
agentTools:
  projectIndex: https://docs.gtm.ai/llms.txt
---

# Authentication

ZoomInfo uses OAuth 2.0 to authenticate every API request. Create an application, obtain an access token using the appropriate OAuth flow, and include the token as a Bearer token in every request.&#x20;

### Choose the right authentication flow

The authentication flow depends on how your application accesses ZoomInfo APIs.

| Use case                                                         | Authentication flow                                                      |
| :--------------------------------------------------------------- | :----------------------------------------------------------------------- |
| Your application accesses ZoomInfo on behalf of a signed-in user | [**Authorization Code Flow (PKCE)**](/docs/authorization-code-flow-pkce) |
| Your application runs server-to-server without user interaction  | [**Client Credentials Flow**](/docs/client-credentials-flow)             |
| You're building a Partner application for customer organizations | [**Authorization Code Flow (PKCE)**](/docs/authorization-code-flow-pkce) |

### Using the access token

After creating your application, use [Test API Access](/docs/test-api-access) to generate an access token and make your first API request before integrating with your own application.

After authentication, include the access token in the Authorization header for every API request.

```http
Authorization: Bearer YOUR_ACCESS_TOKEN
```

<br />

<br />

<br />

<br />

# Sibling pages

* [ZoomInfo API](https://docs.gtm.ai/zoominfoenterprise/reference/api-overview.md)
* [OpenAPI Specification](https://docs.gtm.ai/zoominfoenterprise/reference/openapi-specification.md)