# Authorizing API calls in Swagger

> If you are using Swagger to try our API, just log in to your Orchestrator instance in a separate tab.

## Accessing Swagger

If you are using Swagger to try our API, just log in to your Orchestrator instance in a separate tab.

The Orchestrator API Swagger definition can be accessed by adding the `/swagger/ui/index#/` suffix to your Orchestrator URL. For example, https://{yourDomain} `/swagger/ui/index#/`.

## Obtaining an Access Token

To authorize API calls via the Swagger UI in your Orchestrator instance, perform the following steps:

1. Look for the **Authorize** button at the top right corner of the Orchestrator API page (`OrchestratorURL/swagger`). If the lock is open, you are unauthorized.

   ![docs image](https://dev-assets.cms.uipath.com/assets/images/orchestrator/orchestrator-219801-970087ba.webp)
2. Click **Authorize**. The **Available authorizations** window is displayed.

   :::note
   We currently support one authorization scheme called OAuth2.
   :::

   ![docs image](https://dev-assets.cms.uipath.com/assets/images/orchestrator/orchestrator-219773-ef3a0ff2.webp)
3. All scopes are preselected such that you can experiment with all endpoints in the Orchestrator API. Clear them if you want to restrict access to certain APIs.
4. Click **Authorize**. A new window is displayed confirming you have been authorized.
5. Once done, click **Close** or **X** to close the **Available authorizations** window. The **Authorize** button shows an closed lock meaning you are authorized.

## Sending requests

While authorized, you can make requests on Orchestrator API resources as follows:

1. Expand an Orchestrator API resource with which you want to perform an operation. The closed lock means that you’re authorized.

   Figure 1. Unauthorized API resource

   ![Screenshot of the GET/odata/Folders API](https://dev-assets.cms.uipath.com/assets/images/orchestrator/orchestrator-219805-007d6fd1.webp)
2. In the expanded method window, select **Try it out**.
3. Specify parameter values if required.
4. Select **Execute**. The request is executed. A bearer authorization header is automatically used for your requests.

   Figure 2. Bearer authorization header

   ![Screenshot of a bearer authorization header](https://dev-assets.cms.uipath.com/assets/images/orchestrator/orchestrator-219781-c4b2e0ca.webp)

## Generating a New Access Token

When the access token expires you receive a `401: You are not authenticated!` response. The bearer authorization header is still present for your requests, but the access token is expired. When this happens, you need to invalidate the expired token and generate a new access token:

1. Look for the **Authorize** button at the top right corner of the Orchestrator API page (`OrchestratorURL/swagger`). The lock should be closed.

   ![docs image](https://dev-assets.cms.uipath.com/assets/images/orchestrator/orchestrator-220026-c2fb8f87.webp)
2. Click **Authorize** and on the displayed **Available authorizations** page, click **Logout** to revoke the expired token.

   ![docs image](https://dev-assets.cms.uipath.com/assets/images/orchestrator/orchestrator-220151-386f5a52.webp)
3. Close the **Available authorizations** window by clicking **Close** or **X** and then obtain an access token as described on the [Obtaining an access token](authorizing-api-calls-in-swagger.md) section.

## Revoking Access

When you're done working with the Swagger UI, you should invalidate the access token you've used:

1. Look for the **Authorize** button at the top right corner of the Orchestrator API page (`OrchestratorURL/swagger`). The lock should be closed, meaning you are authorized.
2. Click **Authorize** and on the displayed **Available authorizations** page, click **Logout**.
3. Close the **Available authorizations** window by clicking **Close** or **X**. The **Authorize** button shows an open lock meaning you are unauthorized.
