POST {{authBaseURL}}/oauth2/token
This endpoint obtains or refreshes an API token.
The resulting API token may be either a:
- Merchant token if it is created from a merchant API key
- Partner token if it is created from a partner API key
For making an endpoint call, the two token types are neither the same nor interchangeable. The endpoint description specifies the required API key type. By default, a merchant API key is required.
Obtaining a new API token or refreshing an existing one uses the same endpoint. However, body fields are different:
- Obtaining a new API token uses:
grant_type = client_credentialsscope = offline_access
- Refreshing an existing API token uses:
grant_type = refresh_token- adds the refresh token
- does not use
scope
The examples below illustrate these request body fields. The differences are in bold.
|
Obtain token Set the body type to `x-www-form-urlencoded`. Body fields: grant_type = client_credentials scope = offline_access client_id = u0LJUTc...BKhM3L client_secret = eyJhbG...d7iXs |
Refresh token Set the body type to `x-www-form-urlencoded`. Body fields: grant_type = refresh_token refresh_token = YhjQpM...EVkVuB client_id = u0LJUTc...BKhM3L-y client_secret = eyJhbG...d7iXs |
Specifies client ID from the API key for the account.
Example: 59483870959438697242c
Specifies the client secret from the API key for the account.
Example: 9eb2c6859daa4d8ae5da02a9
Specifies the literal value client_credentials.
If refreshing an API token, use: `refresh_token`
Example: client_credentials
- Mock serverhttps://developer.flute.com/_mock/api-reference/oauth2/token
- Sandbox environmenthttps://sandbox.api.flute.com/oauth2/token
- Production environmenthttps://api.flute.com/oauth2/token
curl -i -X POST \
https://developer.flute.com/_mock/api-reference/oauth2/token \
-H 'Authorization: Bearer <YOUR_JWT_HERE>' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d client_id=59483870959438697242c \
-d client_secret=9eb2c6859daa4d8ae5da02a9 \
-d grant_type=client_credentials \
-d scope=offline_accessOK. Access token issued successfully.
Indicates the API token.
Example: 213bf7a8-9b0c-4d1e-2f3a-4b5c6d7e8f14
Indicates the expiration period (in seconds) of the API token.
Example: 900
Indicates the refresh token (only for authorization_code grant).
Example: 324c08b9-0c1d-4e2f-3a4b-5c6d7e8f9a25
{ "access_token": "213bf7a8-9b0c-4d1e-2f3a-4b5c6d7e8f14", "token_type": "Bearer", "expires_in": 900, "refresh_token": "324c08b9-0c1d-4e2f-3a4b-5c6d7e8f9a25", "scope": null }