> ## Content Index
> Fetch the complete content index at: https://dx.dev.dxm.digitalrealty.com/blog/llms.txt
> Use this file to discover other available public pages before exploring further.

# Getting Started with DX Portal and APIs
- URL: https://dx.dev.dxm.digitalrealty.com/blog/getting-started/
- Published: 2026-09-03T17:10:11.000Z
- Updated: 2026-09-25T09:50:46.000Z
- Author: Admin
- Tags: audience:internal, dxm/getting-started, audience:external

This guide provides an overview of how to access, authenticate, and consume APIs through the DXM  
platform.

## Overview

The DXM platform provides a centralized interface for working with APIs across Digital Realty  
services. The **DX Portal** serves as the primary entry point to:

- Discover available APIs
- Review API documentation
- Test endpoints using Swagger UI
- Retrieve credentials for integration

All API requests are executed through the **DXM Gateway**, which enforces authentication and  
authorization.

---

## Step 1: Explore APIs in DX Portal

The **API section in the DX Portal** provides access to all available APIs. It enables:

- Browsing APIs and their specifications (OpenAPI)
- Reviewing endpoints, parameters, and request/response formats
- Identifying required authentication methods
- Testing endpoints directly via Swagger UI

Each API specification includes details about required credentials and supported environments.

### Testing APIs via Swagger UI

Each API can be tested directly from the portal using the built-in **Swagger UI**, without any  
external tooling.

The presence of an **Authorize** button in Swagger UI indicates whether the API requires  
authentication:

- **Authorize button is present**: The API is protected. Click **Authorize**, paste your access  
token, and all subsequent requests made from Swagger UI will include it automatically.
- **No Authorize button**: The API is publicly accessible and does not require a token. This  
applies to certain endpoints such as the token exchange endpoints used to obtain access tokens  
from your client credentials.

### Client Credentials Tab (API-Level)

Each API in the portal includes a **Client Credentials** tab at the API level. This tab contains a  
helper note that specifies exactly which credentials are required for that particular API and  
environment.

> **Always check the Client Credentials tab before authenticating.** The required credential set  
> varies by API and environment.

The note lists which credentials are available for that specific API, for example:

> API is available on the following environments:Global SSO QAGlobal SSO Production  
>  
> Client Secret and Client ID are available in Settings -> **Client Credentials**.

This tells you which credential sets are available for the API. Use the credentials associated  
with the environment you are accessing. Since DXM uses a 1:1 environment mapping, credentials  
are only valid for their corresponding environment. Using credentials from a different environment  
will result in authentication failures.

---

## Step 2: Retrieve Client Credentials

Client credentials are available in **DX Portal -> Settings**.

These include:

- **Client ID**: Public identifier associated with an application
- **Client Secret**: Confidential credential used for authentication

These credentials are required to obtain access tokens.

> **Security considerations**  
>  
> Client Secrets must be handled securely. They must not be exposed in client-side code, logs, or  
> version control systems.

---

## Step 3: Obtain an Access Token

Most APIs require an access token for authentication. The correct token endpoint to use is  
determined by the **Client Credentials** tab of the specific API. The same note that lists  
available environments also tells you which credential type is in use:

- If the note lists **Global SSO** environments, use the **Global SSO Access Token** endpoint  
(*DX Portal -> API -> Global SSO Access Token*).
- If the note lists **DXM** environments, use the **DXM Access Token** endpoint  
(*DX Portal -> API -> DXM Access Token*).

If required credentials or access are not available, they can be requested via the **Contact Us**  
form.

### Access Token Flow

Authentication follows a client credentials flow:

1. Check the API's **Client Credentials** tab to identify the correct token endpoint.
2. Submit your Client ID and Client Secret to that endpoint.
3. Receive an access token (JWT).
4. Use the token in API requests.

---

## Step 4: Execute API Requests

APIs can be consumed in several ways. Use whichever best fits your workflow. All protected API  
requests must include the access token in the Authorization header:

```text
Authorization: Bearer <access_token>

```

### Swagger UI (in DX Portal)

This is the quickest way to explore and test without leaving the portal.

Swagger UI automatically uses the server URL associated with the environment you are accessing.  
No additional server selection or environment configuration is required.

### cURL

Suitable for quick command-line testing or scripting:

```bash
curl -X GET "https://gateway.digitalrealty.com/accounts/v1/example" \
  -H "Authorization: Bearer <access_token>" \
  -H "Content-Type: application/json"

```

### API Clients (Postman, Insomnia, etc.)

Any HTTP client can be used. Configure the `Authorization` header with  
`Bearer <access_token>` and use the base URL corresponding to your target environment.

### Programmatic / SDK Usage

APIs can be called from any language or framework.