# Authentication

Triple-A APIs use OAuth 2.0 with the Client Credentials grant. The same token mechanism applies to Stablecoin Payments, Stablecoin Payouts, and Local Currency Payouts, so you set it up once. This page shows how to get an access token and cache it by its real expiry.

You need a Client ID and Client Secret first. See [Get your API credentials](/docs/getting-started/get-your-api-credentials/).

## Request a token

Call [Get an access token](/api/stablecoin-payments/authentication/post-oauth-token/) with your Client ID and Client Secret. The table below shows the request settings.

| Setting | Value |
|---|---|
| Endpoint | [Get an access token](/api/stablecoin-payments/authentication/post-oauth-token/) |
| Content type | `application/x-www-form-urlencoded` |
| Grant type | `client_credentials` |

The following request gets a token. The highlighted lines are the form content type and the `grant_type`, which must be `client_credentials`.

```bash title="Request" {4,7}
curl --request POST \
  --url https://api.triple-a.io/api/v2/oauth/token \
  --header 'Accept: application/json' \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'client_id=YOUR_CLIENT_ID' \
  --data-urlencode 'client_secret=YOUR_CLIENT_SECRET' \
  --data-urlencode 'grant_type=client_credentials'
```

The response contains the token and its lifetime. The highlighted lines are the `access_token` to send with each request and its `expires_in` lifetime.

```json title="Response" {2,4}
{
  "access_token": "1ba8...",
  "token_type": "bearer",
  "expires_in": 3600
}
```

The table below describes each field in the response.

| Field | Description |
|---|---|
| `access_token` | The token to send with every later request. |
| `token_type` | Always `bearer`. |
| `expires_in` | How long the token lasts, in seconds. |

Make this call from your server. Never put the Client Secret in client-side code.

## Use the token

Send the token in the `Authorization` header of every request.

```text title="Authorization header"
Authorization: Bearer YOUR_ACCESS_TOKEN
```

Requests without a valid token are rejected. For the errors you can get, see [Error codes](/docs/reference/error-codes/#authentication-errors).

## Handle token expiry

Cache the token and reuse it until it expires. Don't request a new token for every call. A token is currently valid for 1 hour, but rather than hardcoding that value, read `expires_in` from each response and refresh the token shortly before it runs out. When it expires, request a new one with the same credentials.

If you rotate your credentials, every token issued with the old pair stops working immediately.

## Next steps

These pages are the best places to go next.

- [Sandbox and test mode](/docs/stablecoin-payments/sandbox-and-test-mode/) to prepare for test payments
- [Your first payment](/docs/stablecoin-payments/your-first-payment/) to make your first call with the token