Skip to content
iSmartPay Developers
Esc
↑↓navigate↵open⌘Jpreview
On this page

Authentication

Exchange a client ID and secret for a short-lived bearer token.

Every route takes a bearer token. You get one by trading a key for a token.

Request a token

POST /v1/oauth/token takes a form body (application/x-www-form-urlencoded).

Field Value
grant_type client_credentials
client_id Your key’s client ID
client_secret Your key’s client secret
resource ismartpay
curl -X POST "$API/v1/oauth/token" \
  --data-urlencode "grant_type=client_credentials" \
  --data-urlencode "client_id=$CLIENT_ID" \
  --data-urlencode "client_secret=$CLIENT_SECRET" \
  --data-urlencode "resource=ismartpay"

The response:

{
  "access_token": "eyJ...",
  "token_type": "Bearer",
  "expires_in": 300
}

Send it on every call:

Authorization: Bearer <access_token>

Token lifetime

A token lasts 5 minutes. There is no refresh token. When it is close to expiring, ask for a new one with the same key.

  • Cache the token in memory.
  • Fetch a new one a little before expires_in runs out, not after a 401.
  • Do not fetch a token per request. That wastes calls against your rate limit.

Keep secrets on your server

The client secret must never reach a browser, a mobile app or a public repository. Call the API from your backend only.

  • Load the secret from a secret store or environment variable.
  • Do not log it.
  • If it leaks, rotate it at once.

Rotate a key

  1. Create a new key in the console.
  2. Deploy the new client ID and secret.
  3. Check that traffic uses the new key.
  4. Revoke the old key.

Revoking is final. Create the new key first so you never have a gap.

Was this page helpful?