---
metadata:
  - name: generator
    content: Diplodoc Platform v5.54.1
alternate:
  - https://yandex.ru/dev/metrika/en/intro/authorization.md
  - https://yandex.ru/dev/metrika/ru/intro/authorization.md
  - href: en/intro/authorization.md
    type: text/markdown
    title: Markdown version
  - href: ../llms.txt
    type: text/markdown
    title: llms.txt
---
> **Documentation Index:** Fetch the complete configuration index at https://yandex.ru/dev/metrika/en/llms.txt

# Authorization

To use the Yandex Metrica API, you need to get an [authorization token](https://yandex.com/dev/id/doc/en/concepts/ya-oauth-intro) through the Yandex OAuth server. The token must be passed for each method in the HTTP `Authorization` header.

```
GET /management/v1/counters HTTP/1.1
Host: api-metrika.yandex.net
Authorization: OAuth 05dd3dd84ff948fdae2bc4fb91f13e22bb1f289ceef0037
Content-Type: application/x-yametrika+json
Content-Length: 123
```

If an API method is called without a token, or the request includes an invalid token, the server returns the HTTP status `401 Unauthorized`.

{% note info %}

Authorization tokens must be stored securely and not given to third parties.

{% endnote %}

## Obtaining an OAuth token {#get-oauth-token}

To get an authorization token:

<!-- source: en/_includes/oauth.md -->
1. [Create an app](https://oauth.yandex.com/?dialog=create-client-entry) and select **For API access or debugging**. 

1. Fill in the information:
    - **Name**: Any name of your choice.
    - **Email**: Specify your preferred contact email.
    - **Data access**: Specify a set of accesses for your app. 
    
        Types of accesses:

        - **metrika:read**: Getting statistics, reading parameters of your own and trusted tags, getting a list of tags.
        - **metrika:write**: Creating tags, changing parameters of your own and trusted tags, uploading any data.
        - **metrika:expenses**: Uploading expenses to tags.
        - **metrika:user_params**: Uploading user parameters to tags.
        - **metrika:offline_data**: Uploading offline data (CRM data, offline conversions, calls) to tags.

        **metrika:expenses**, **metrika:user_params**, and **metrika:offline_data** accesses are optional if **metrika:write** is used.

    {% note info %}

    If you're using porg usernames (organization usernames), add **passport:business** to the access permissions. This is required to issue a token from the organization.

    {% endnote %}

1. Click **Create app** and copy its ClientID (next to the ID, click ![](../../_images/copy.svg)).

1. Add the copied ClientID to the link as follows

    ```http translate=no
    https://oauth.yandex.com/authorize?response_type=token&client_id=<application_id>
    ```

1. Follow the link and copy your authorization token on the page that opens.
<!-- endsource: en/_includes/oauth.md -->

## Troubleshooting {#troubles}

<!-- source: en/_includes/oauth.md -->
{% cut "Error 403 (Access is denied) after obtaining a token" %}

Possible reasons:

**App-side**

- The app doesn't have access to Yandex Metrica. To read tag data (for example, to generate reports or view tag information), your app requires `metrika:read` access. To manage tags (for example, to upload offline data or edit tags and segments), your app requires `metrika:write` access.

**Token-side**

- The token is invalid. The token expired or the authorization password for the associated account was changed. Issue another token.

- The token was issued for another account. It may have been issued for a username that doesn't have access to the Yandex Metrica tag.

     {% note warning %}

     The token owner is not the app owner but the account that you used to make the GET request to obtain the token.

     {% endnote %}

- The token was created for another app. The GET request to obtain the token included an incorrect `client_id` value or a typo that resulted in the token being issued for an app that doesn't have `metrika:read` or `metrika:write` access to Yandex Metrica.

**Yandex Metrica-side**

- The token owner doesn't have access to the tag that you're attempting to access via the API. [Learn more](https://yandex.com/support/metrica/general/access.html) about the types of tag access. The Management API requires owner, guest view, or guest write access.

**API request-side**

- The token is read incorrectly or not at all due to incorrect authorization parameters in the API call code.

{% endcut %}

{% cut "Error 401 (unauthorized) after obtaining a token" %}

Possible reasons:

1. The authorization parameters in the request header are incorrect.
2. The header is missing authorization parameters.

{% endcut %}
<!-- endsource: en/_includes/oauth.md -->
