Appearance
Authentication
Every signed v2 endpoint requires an access token in the Authorization header, in addition to the request signature.
http
Authorization: Bearer <access_token>Getting a token
Exchange your vendor account email and password for an access token and a refresh token:
bash
curl -X POST https://staging-oapi.dmcpay.net/api/v2/auth/token \
-H 'Content-Type: application/json' \
-d '{"grant_type":"password","username":"<your-account-email>","password":"<your-password>"}'The response contains:
| Field | Description |
|---|---|
access_token | Send as Authorization: Bearer …. Valid for 15 minutes |
access_token_expires_at | When the access token stops working (RFC 3339) |
refresh_token | Use to get a new access token. Valid for 8 hours |
refresh_token_expires_at | When the refresh token stops working (RFC 3339) |
See Get access token for the full request and response.
Keeping the token fresh
Before access_token_expires_at, call the same endpoint with grant_type: "refresh_token" — see Refresh access token. Each refresh returns a new refresh token and invalidates the old one, so always store the latest one. If refreshing fails, log in again with your password.
Logging in again also invalidates access tokens issued before that login.
Recommended pattern
Keep one token per backend (not per request), refresh it a minute or two before it expires, and if a call returns HTTP 401 with code: "FAILED", get a fresh token and retry once.
When the token is rejected
An invalid, expired or superseded access token returns HTTP 401 with "code": "FAILED":
json
{ "message": "token has expired", "code": "FAILED" }Server-side only
Your credentials, tokens and private key must only ever live on your servers — never in a browser, mobile app or customer-facing client.
