Authentication

Triple-A APIs use OAuth 2.0 with the Client Credentials grant. The same token mechanism applies to Stablecoin Payments, Stablecoin Payouts, and Local Currency Payouts, so you set it up once. This page shows how to get an access token and cache it by its real expiry.

You need a Client ID and Client Secret first. See Get your API credentials.

Request a token

Call Get an access token with your Client ID and Client Secret. The table below shows the request settings.

SettingValue
EndpointGet an access token
Content typeapplication/x-www-form-urlencoded
Grant typeclient_credentials

The following request gets a token. The highlighted lines are the form content type and the grant_type, which must be client_credentials.

Request
curl --request POST \
  --url https://api.triple-a.io/api/v2/oauth/token \
  --header 'Accept: application/json' \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'client_id=YOUR_CLIENT_ID' \
  --data-urlencode 'client_secret=YOUR_CLIENT_SECRET' \
  --data-urlencode 'grant_type=client_credentials'

The response contains the token and its lifetime. The highlighted lines are the access_token to send with each request and its expires_in lifetime.

Response
{
  "access_token": "1ba8...",
  "token_type": "bearer",
  "expires_in": 3600
}

The table below describes each field in the response.

FieldDescription
access_tokenThe token to send with every later request.
token_typeAlways bearer.
expires_inHow long the token lasts, in seconds.

Make this call from your server. Never put the Client Secret in client-side code.

Use the token

Send the token in the Authorization header of every request.

Authorization header
Authorization: Bearer YOUR_ACCESS_TOKEN

Requests without a valid token are rejected. For the errors you can get, see Error codes.

Handle token expiry

Cache the token and reuse it until it expires. Don’t request a new token for every call. A token is currently valid for 1 hour, but rather than hardcoding that value, read expires_in from each response and refresh the token shortly before it runs out. When it expires, request a new one with the same credentials.

If you rotate your credentials, every token issued with the old pair stops working immediately.

Next steps

These pages are the best places to go next.