Skip to content

Authentication ​

Every signed v2 endpoint requires an access token in the Authorization header, in addition to the request signature.

http
Authorization: Bearer <access_token>

Getting a token ​

Exchange your vendor account email and password for an access token and a refresh token:

bash
curl -X POST https://staging-oapi.dmcpay.net/api/v2/auth/token \
  -H 'Content-Type: application/json' \
  -d '{"grant_type":"password","username":"<your-account-email>","password":"<your-password>"}'

The response contains:

FieldDescription
access_tokenSend as Authorization: Bearer …. Valid for 15 minutes
access_token_expires_atWhen the access token stops working (RFC 3339)
refresh_tokenUse to get a new access token. Valid for 8 hours
refresh_token_expires_atWhen the refresh token stops working (RFC 3339)

See Get access token for the full request and response.

Keeping the token fresh ​

Before access_token_expires_at, call the same endpoint with grant_type: "refresh_token" — see Refresh access token. Each refresh returns a new refresh token and invalidates the old one, so always store the latest one. If refreshing fails, log in again with your password.

Logging in again also invalidates access tokens issued before that login.

Recommended pattern

Keep one token per backend (not per request), refresh it a minute or two before it expires, and if a call returns HTTP 401 with code: "FAILED", get a fresh token and retry once.

When the token is rejected ​

An invalid, expired or superseded access token returns HTTP 401 with "code": "FAILED":

json
{ "message": "token has expired", "code": "FAILED" }

Server-side only

Your credentials, tokens and private key must only ever live on your servers — never in a browser, mobile app or customer-facing client.

Need help? Contact your DMC Pay account manager.