Authentication¶
The Hivemind Payments API uses two auth mechanisms depending on the endpoint:
- HTTP Basic Auth — used only for the token endpoint, with your API client ID and client secret (not a user login).
- Bearer token — used for every other endpoint, using the access token returned by the token endpoint.
Get an access token¶
| Field | Value |
|---|---|
| Method | GET |
| Endpoint | /auth/token/ |
| Auth type | HTTP Basic Auth |
| Username | Your API Client ID (created in the merchant portal) |
| Password | Your API Client Secret (created in the merchant portal) |
Basic Auth here authenticates your application, not a person — your client ID goes in the username field and your client secret goes in the password field of the Basic Auth header.
Example request¶
curl -X GET "https://api.cloudpay365.com/api/v1/auth/token/" \
-u "<YOUR_CLIENT_ID>:<YOUR_CLIENT_SECRET>"
Example response¶
{
"success": true,
"message": "Token generated",
"data": {
"access_token": "<ACCESS_TOKEN>",
"token_type": "Bearer",
"expires_in": 3600
}
}
expires_in is in seconds — access tokens are valid for 1 hour. There is no refresh_token in the response, so treat expiry as a signal to call GET /auth/token/ again with your Basic Auth credentials rather than looking for a refresh flow.
Example error response¶
Returned as 401 Unauthorized when the client ID/secret pair is wrong.
Use the access token¶
Every other endpoint requires the token as a Bearer credential:
curl -X GET "https://api.cloudpay365.com/api/v1/merchants/wallets/" \
-H "Authorization: Bearer <ACCESS_TOKEN>"
See the Authentication API reference for the full parameter and response tables, and Token Handling Best Practices for how to store and rotate credentials safely.