Authentication¶
Description¶
Exchanges your API client ID and client secret for a short-lived Bearer access token. Every other endpoint requires this token. See Getting Started → Authentication for a walkthrough of the overall auth flow.
Auth¶
HTTP Basic Auth. This is the only endpoint that does not take a Bearer token.
| Basic Auth field | Value |
|---|---|
| Username | Your API client ID (created in the merchant portal) |
| Password | Your API client secret (created in the merchant portal) |
Endpoint & Method¶
Parameters¶
| Parameter | Location | Type | Required | Notes |
|---|---|---|---|---|
Authorization |
Header | string | Required | Basic base64(<client_id>:<client_secret>); curl's -u builds this for you |
The request has no query parameters and no body.
Example Request¶
curl -X GET "https://api.cloudpay365.com/api/v1/auth/token/" \
-u "<YOUR_CLIENT_ID>:<YOUR_CLIENT_SECRET>"
Example Response¶
200 OK¶
{
"success": true,
"message": "Token generated",
"data": {
"access_token": "<ACCESS_TOKEN>",
"token_type": "Bearer",
"expires_in": 3600
}
}
| Field | Notes |
|---|---|
data.access_token |
Send as Authorization: Bearer <access_token> on every other endpoint |
data.token_type |
Always Bearer in the captured example |
data.expires_in |
Token lifetime in seconds (3600 = 1 hour) |
401 Unauthorized¶
Returned when the client ID/secret pair is wrong.
Notes / Gotchas¶
- No
refresh_tokenis issued. When a token expires, callGET /auth/token/again with your Basic Auth credentials. - Cache the token and reuse it until shortly before
expires_inelapses. Don't request a new token on every API call. - Your client ID and secret authenticate your application, not a user login. Keep them server-side only; see Token Handling Best Practices.
- Requests from IPs that aren't on your whitelist are rejected with
403; see IP Whitelisting.