Authentication
Exchange a client ID and secret for a short-lived bearer token.
Every route takes a bearer token. You get one by trading a key for a token.
Request a token
POST /v1/oauth/token takes a form body (application/x-www-form-urlencoded).
| Field | Value |
|---|---|
grant_type |
client_credentials |
client_id |
Your key’s client ID |
client_secret |
Your key’s client secret |
resource |
ismartpay |
curl -X POST "$API/v1/oauth/token" \
--data-urlencode "grant_type=client_credentials" \
--data-urlencode "client_id=$CLIENT_ID" \
--data-urlencode "client_secret=$CLIENT_SECRET" \
--data-urlencode "resource=ismartpay"
The response:
{
"access_token": "eyJ...",
"token_type": "Bearer",
"expires_in": 300
}
Send it on every call:
Authorization: Bearer <access_token>
Token lifetime
A token lasts 5 minutes. There is no refresh token. When it is close to expiring, ask for a new one with the same key.
- Cache the token in memory.
- Fetch a new one a little before
expires_inruns out, not after a401. - Do not fetch a token per request. That wastes calls against your rate limit.
Keep secrets on your server
The client secret must never reach a browser, a mobile app or a public repository. Call the API from your backend only.
- Load the secret from a secret store or environment variable.
- Do not log it.
- If it leaks, rotate it at once.
Rotate a key
- Create a new key in the console.
- Deploy the new client ID and secret.
- Check that traffic uses the new key.
- Revoke the old key.
Revoking is final. Create the new key first so you never have a gap.