---
title: First API Call
slug: api-docs/first-api-call
description: Walkthrough of a first Litmus API request from auth to response, with cURL, Python, and JavaScript examples. Run the same call live in our Postman collection.
docTags: 
createdAt: 2026-05-11T22:00:06.873Z
---

# Your First API Call

A 60-second sanity check: get a token, hit one endpoint, see a 200.

:::BlockQuote
**Run this call live:** every example on this page also lives in the [Litmus API collection](https://api.litmus.io/view/2s9Y5R1RvG). Open the collection, fork it, paste your token, and hit Send.
:::

## 1. Get a token

```bash
TOKEN=$(curl -sk -X POST "https://<edge-host>/auth/v3/oauth/token" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials" \
  -d "client_id=$CLIENT_ID" \
  -d "client_secret=$CLIENT_SECRET" | jq -r .access_token)
```

`-k` skips TLS verification - use only against self-signed dev instances. See [SSL Certificates](#) before doing this in production.

## 2. Call a read-only endpoint

```bash
curl -sk "https://<edge-host>/devicehub/version" \
  -H "Authorization: Bearer $TOKEN"
```

Expected: a JSON object with a `Version` field. If you see this, auth and routing work.

## 3. Try a GraphQL call

DeviceHub is GraphQL. List drivers on the edge:

```bash
curl -sk -X POST "https://<edge-host>/devicehub/v2" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"query":"query { ListDriverGroups { ID Name Drivers { ID Name } } }"}'
```

:::BlockQuote
GraphQL endpoints return HTTP 200 even on errors. Check the `errors` key in the response body, not just the status code. See [GraphQL vs REST](#).
:::

## Python equivalent

```python
import os, requests

EDGE = os.environ["EDGE_URL"]
r = requests.post(
    f"{EDGE}/auth/v3/oauth/token",
    data={
        "grant_type": "client_credentials",
        "client_id": os.environ["CLIENT_ID"],
        "client_secret": os.environ["CLIENT_SECRET"],
    },
    verify=False,
)
token = r.json()["access_token"]

v = requests.get(f"{EDGE}/devicehub/version",
                 headers={"Authorization": f"Bearer {token}"},
                 verify=False)
print(v.json())
```

## Troubleshooting

| Symptom                          | Likely cause                                                                                   |
| -------------------------------- | ---------------------------------------------------------------------------------------------- |
| `401 Unauthorized`               | Token expired, wrong client\_id/secret, or wrong header (LEM uses `X-AuthToken`, not `Bearer`) |
| `404 Not Found`                  | Wrong base URL or path prefix - see [Base URLs](#)                                             |
| `SSL: CERTIFICATE_VERIFY_FAILED` | Self-signed cert - see [SSL Certificates](#)                                                   |
| GraphQL returns 200 but no data  | Check `errors` key in the body, not just HTTP status                                           |

