Suggested answer

API access is managed via Installed Packages in Marketing Cloud Setup (Platform > Apps > Installed Packages).
Component types:
— Server-to-Server: OAuth 2.0 client credentials flow. Used for back-end integrations. Provides client_id and client_secret.
— Public App: OAuth 2.0 with PKCE. For front-end or mobile apps that cannot store secrets.
— Web App: OAuth 2.0 authorisation code flow. For web apps with server-side components.
Common OAuth scopes:
— email:read/write/send — Email Studio access
— data:read/write — Data Extension access
— list:read/write — Subscriber list management
— contacts:read/write — Contact Builder
— journeys:read/write — Journey Builder
— assets:read/write/publish — Content Builder
IP allowlisting: Restrict API access to specific IP addresses or CIDR ranges in the Installed Package settings for additional security.
Token management: Access tokens expire in 1,080 seconds (18 minutes). Cache and reuse — do not request a new token per API call.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.