Authentication
Triple-A APIs use OAuth 2.0 with the Client Credentials grant. The same token mechanism applies to Stablecoin Payments, Stablecoin Payouts, and Local Currency Payouts, so you set it up once. This page shows how to get an access token and cache it by its real expiry.
You need a Client ID and Client Secret first. See Get your API credentials.
Request a token
Call Get an access token with your Client ID and Client Secret. The table below shows the request settings.
| Setting | Value |
|---|---|
| Endpoint | Get an access token |
| Content type | application/x-www-form-urlencoded |
| Grant type | client_credentials |
The following request gets a token. The highlighted lines are the form content type and the grant_type, which must be client_credentials.
curl --request POST \
--url https://api.triple-a.io/api/v2/oauth/token \
--header 'Accept: application/json' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=YOUR_CLIENT_ID' \
--data-urlencode 'client_secret=YOUR_CLIENT_SECRET' \
--data-urlencode 'grant_type=client_credentials'The response contains the token and its lifetime. The highlighted lines are the access_token to send with each request and its expires_in lifetime.
{
"access_token": "1ba8...",
"token_type": "bearer",
"expires_in": 3600
}The table below describes each field in the response.
| Field | Description |
|---|---|
access_token | The token to send with every later request. |
token_type | Always bearer. |
expires_in | How long the token lasts, in seconds. |
Make this call from your server. Never put the Client Secret in client-side code.
Use the token
Send the token in the Authorization header of every request.
Authorization: Bearer YOUR_ACCESS_TOKENRequests without a valid token are rejected. For the errors you can get, see Error codes.
Handle token expiry
Cache the token and reuse it until it expires. Don’t request a new token for every call. A token is currently valid for 1 hour, but rather than hardcoding that value, read expires_in from each response and refresh the token shortly before it runs out. When it expires, request a new one with the same credentials.
If you rotate your credentials, every token issued with the old pair stops working immediately.
Next steps
These pages are the best places to go next.
- Sandbox and test mode to prepare for test payments
- Your first payment to make your first call with the token