Skip to content

Get access token ​

Exchange your vendor account email and password for an access token and refresh token.

POST/api/v2/auth/tokenNo auth

Request body ​

FieldTypeRequiredDescription
grant_typestringrequiredMust be password
usernamestringrequiredYour vendor account email
passwordstringrequiredYour vendor account password
json
{
  "grant_type": "password",
  "username": "vendor@example.com",
  "password": "••••••••"
}

Response ​

200 OK
json
{
  "code": "OK",
  "data": {
    "session_id": "95fbef04-c2ea-499d-9362-eeac70344a55",
    "access_token": "v2.local.NTvaU6-xmM2yIkLMQMm8VB_YH3R114MKd…",
    "access_token_expires_at": "2026-06-20T10:14:57.873669Z",
    "refresh_token": "v2.local.XjpubecZzsZAAeAGfhObnolLuqeo6ku1i…",
    "refresh_token_expires_at": "2026-06-20T18:04:57.873939Z"
  }
}
FieldTypeDescription
data.session_idstringSession identifier
data.access_tokenstringSend as Authorization: Bearer … (valid 15 minutes)
data.access_token_expires_atstringExpiry of the access token (RFC 3339, UTC)
data.refresh_tokenstringUse with Refresh access token (valid 8 hours)
data.refresh_token_expires_atstringExpiry of the refresh token (RFC 3339, UTC)

Errors ​

HTTPCodeWhen
401credential.invalid_username_or_passwordEmail or password is wrong
400unknown_errorMissing or malformed fields
500server_errorServer error — retry later

Need help? Contact your DMC Pay account manager.