Skip to content

Obtains or refreshes an API token

Request

POST {{authBaseURL}}/oauth2/token

This endpoint obtains or refreshes an API token.

The resulting API token may be either a:

  • Merchant token if it is created from a merchant API key
  • Partner token if it is created from a partner API key

For making an endpoint call, the two token types are neither the same nor interchangeable. The endpoint description specifies the required API key type. By default, a merchant API key is required.

Obtaining a new API token or refreshing an existing one uses the same endpoint. However, body fields are different:

  • Obtaining a new API token uses:
    • grant_type = client_credentials
    • scope = offline_access
  • Refreshing an existing API token uses:
    • grant_type = refresh_token
    • adds the refresh token
    • does not use scope

The examples below illustrate these request body fields. The differences are in bold.

Obtain token
Set the body type to `x-www-form-urlencoded`.

Body fields:
grant_type = client_credentials
scope = offline_access
client_id = u0LJUTc...BKhM3L
client_secret = eyJhbG...d7iXs
Refresh token
Set the body type to `x-www-form-urlencoded`.

Body fields:
grant_type = refresh_token
refresh_token = YhjQpM...EVkVuB
scope = offline_access
client_id = u0LJUTc...BKhM3L-y
client_secret = eyJhbG...d7iXs
Security
Bearer
Bodyapplication/x-www-form-urlencodedrequired
client_idstringrequired

Specifies client ID from the API key for the account.

Example: 59483870959438697242c

Example:"59483870959438697242c"
client_secretstringrequired

Specifies the client secret from the API key for the account.

Example: 9eb2c6859daa4d8ae5da02a9

Example:"9eb2c6859daa4d8ae5da02a9"
grant_typestringrequired

Specifies the literal value client_credentials.

If obtaining an API token, use: `client_credentials`
If refreshing an API token, use: `refresh_token`

Example: client_credentials

Example:"client_credentials"
scopestringrequired

Specifies the literal value offline_access.

Use only for obtaining an API token.
Omit when refreshing an API token.

Example: offline_access

Example:"offline_access"
curl -i -X POST \
  https://developer.flute.com/_mock/api-reference/oauth2/token \
  -H 'Authorization: Bearer <YOUR_JWT_HERE>' \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  -d client_id=59483870959438697242c \
  -d client_secret=9eb2c6859daa4d8ae5da02a9 \
  -d grant_type=client_credentials \
  -d scope=offline_access

Responses

OK. Access token issued successfully.

Bodyapplication/json
access_tokenstringrequired

Indicates the API token.

Example: 213bf7a8-9b0c-4d1e-2f3a-4b5c6d7e8f14

Example:"213bf7a8-9b0c-4d1e-2f3a-4b5c6d7e8f14"
token_typestringrequired

Indicates the token type.

Example: Bearer

Example:"Bearer"
expires_ininteger

Indicates the expiration period (in seconds) of the API token.

Example: 900

Example:900
refresh_tokenstring

Indicates the refresh token (only for authorization_code grant).

Example: 324c08b9-0c1d-4e2f-3a4b-5c6d7e8f9a25

Example:"324c08b9-0c1d-4e2f-3a4b-5c6d7e8f9a25"
scopestring

Indicates the granted scopes, space-delimited.

Example: null

Example:null
Response
{ "access_token": "213bf7a8-9b0c-4d1e-2f3a-4b5c6d7e8f14", "token_type": "Bearer", "expires_in": 900, "refresh_token": "324c08b9-0c1d-4e2f-3a4b-5c6d7e8f9a25", "scope": null }