Skip to content

Authentication

The Hivemind Payments API uses two auth mechanisms depending on the endpoint:

  1. HTTP Basic Auth — used only for the token endpoint, with your API client ID and client secret (not a user login).
  2. Bearer token — used for every other endpoint, using the access token returned by the token endpoint.

Get an access token

Field Value
Method GET
Endpoint /auth/token/
Auth type HTTP Basic Auth
Username Your API Client ID (created in the merchant portal)
Password Your API Client Secret (created in the merchant portal)

Basic Auth here authenticates your application, not a person — your client ID goes in the username field and your client secret goes in the password field of the Basic Auth header.

Example request

curl -X GET "https://api.cloudpay365.com/api/v1/auth/token/" \
  -u "<YOUR_CLIENT_ID>:<YOUR_CLIENT_SECRET>"

Example response

{
  "success": true,
  "message": "Token generated",
  "data": {
    "access_token": "<ACCESS_TOKEN>",
    "token_type": "Bearer",
    "expires_in": 3600
  }
}

expires_in is in seconds — access tokens are valid for 1 hour. There is no refresh_token in the response, so treat expiry as a signal to call GET /auth/token/ again with your Basic Auth credentials rather than looking for a refresh flow.

Example error response

{
  "success": false,
  "message": "Invalid username/password."
}

Returned as 401 Unauthorized when the client ID/secret pair is wrong.

Use the access token

Every other endpoint requires the token as a Bearer credential:

Authorization: Bearer <ACCESS_TOKEN>
curl -X GET "https://api.cloudpay365.com/api/v1/merchants/wallets/" \
  -H "Authorization: Bearer <ACCESS_TOKEN>"

See the Authentication API reference for the full parameter and response tables, and Token Handling Best Practices for how to store and rotate credentials safely.