OAuth 2.0 and OIDC

Coupa uses OAuth 2.0 and OIDC to authenticate API requests. API Keys are no longer supported.

API Security with OIDC/OAuth 2.0

Coupa uses OpenID Connect (OIDC), an open authentication protocol that extends OAuth 2.0 for an improved level of security for API integrations with Coupa.

Note:

API keys are deprecated. You must transition any existing keys to OAuth clients and revoke the keys under Setup > API Keys. This transition only affects customer-created API integrations to the Coupa Core platform, and does not not affect applications such as Treasury, CSO, Supply Chain Design & Planning.