Authentication Token
/authentication/oauth2/access_tokenAuthentication
All transactions are authenticated using a Bearer token generated through the OAuth 2.0 protocol. To obtain a token, clients must send a request to the authentication endpoint using their client_id and client_secret (click here to see how to generate your credentials). To authenticate this request, you must pass the Base64-encoded string of client_id:client_secret in the Authorization header. The generated access token must be included in the Authorization header of each API request, ensuring secure and controlled access to the API.
Usage
Once the token is obtained, include it in the Authorization header of your API requests as follows:Authorization: Bearer {access_token}
Token Expiration & Renewal
- The token is valid for the duration specified in expires_in (usually 3599 seconds or ~1 hour).
- When the token expires, you must request a new one using the same authentication process.
v20250823.0859
Header Parameters
The Basic Auth header containing client_id:client_secret encoded in Base64.
Body application/x-www-form-urlencoded
The OAuth 2.0 grant type.
Response
Access token generated successfully.
The Bearer Token to be used in the Authorization header.
The granted scope(s) for the token.
Indicates the token type, which is always “Bearer”.
The token’s lifetime in seconds (e.g., 3599).
Invalid credentials