Appearance
Get access token
Exchange your vendor account email and password for an access token and refresh token.
POST/api/v2/auth/tokenNo auth
Request body
| Field | Type | Required | Description |
|---|---|---|---|
grant_type | string | required | Must be password |
username | string | required | Your vendor account email |
password | string | required | Your vendor account password |
json
{
"grant_type": "password",
"username": "vendor@example.com",
"password": "••••••••"
}Response
200 OKjson
{
"code": "OK",
"data": {
"session_id": "95fbef04-c2ea-499d-9362-eeac70344a55",
"access_token": "v2.local.NTvaU6-xmM2yIkLMQMm8VB_YH3R114MKd…",
"access_token_expires_at": "2026-06-20T10:14:57.873669Z",
"refresh_token": "v2.local.XjpubecZzsZAAeAGfhObnolLuqeo6ku1i…",
"refresh_token_expires_at": "2026-06-20T18:04:57.873939Z"
}
}| Field | Type | Description |
|---|---|---|
data.session_id | string | Session identifier |
data.access_token | string | Send as Authorization: Bearer … (valid 15 minutes) |
data.access_token_expires_at | string | Expiry of the access token (RFC 3339, UTC) |
data.refresh_token | string | Use with Refresh access token (valid 8 hours) |
data.refresh_token_expires_at | string | Expiry of the refresh token (RFC 3339, UTC) |
Errors
| HTTP | Code | When |
|---|---|---|
| 401 | credential.invalid_username_or_password | Email or password is wrong |
| 400 | unknown_error | Missing or malformed fields |
| 500 | server_error | Server error — retry later |
