Skip to content

Authentication

Description

Exchanges your API client ID and client secret for a short-lived Bearer access token. Every other endpoint requires this token. See Getting Started → Authentication for a walkthrough of the overall auth flow.

Auth

HTTP Basic Auth. This is the only endpoint that does not take a Bearer token.

Basic Auth field Value
Username Your API client ID (created in the merchant portal)
Password Your API client secret (created in the merchant portal)

Endpoint & Method

GET /auth/token/

Parameters

Parameter Location Type Required Notes
Authorization Header string Required Basic base64(<client_id>:<client_secret>); curl's -u builds this for you

The request has no query parameters and no body.

Example Request

curl -X GET "https://api.cloudpay365.com/api/v1/auth/token/" \
  -u "<YOUR_CLIENT_ID>:<YOUR_CLIENT_SECRET>"

Example Response

200 OK

{
  "success": true,
  "message": "Token generated",
  "data": {
    "access_token": "<ACCESS_TOKEN>",
    "token_type": "Bearer",
    "expires_in": 3600
  }
}
Field Notes
data.access_token Send as Authorization: Bearer <access_token> on every other endpoint
data.token_type Always Bearer in the captured example
data.expires_in Token lifetime in seconds (3600 = 1 hour)

401 Unauthorized

{
  "success": false,
  "message": "Invalid username/password."
}

Returned when the client ID/secret pair is wrong.

Notes / Gotchas

  • No refresh_token is issued. When a token expires, call GET /auth/token/ again with your Basic Auth credentials.
  • Cache the token and reuse it until shortly before expires_in elapses. Don't request a new token on every API call.
  • Your client ID and secret authenticate your application, not a user login. Keep them server-side only; see Token Handling Best Practices.
  • Requests from IPs that aren't on your whitelist are rejected with 403; see IP Whitelisting.