Obtain access token
OAuth 2.0 token endpoint supporting client credentials and refresh token grant types.
Use this endpoint to obtain an access token that can be used to authenticate requests to other API endpoints. The token should be included in the Authorization header as a Bearer token.
Supported Content Types:
application/x-www-form-urlencoded(standard OAuth 2.0)application/json
Grant Types:
- client_credentials: Use client ID and secret to obtain an access token
- refresh_token: Use a refresh token to obtain a new access token
Token request
TypeScript Definitions
Use the request body type in TypeScript.
Client identifier issued during registration
"your_client_id"Client secret issued during registration
"your_client_secret"OAuth 2.0 grant type (must be 'client_credentials')
"client_credentials""client_credentials"Space-separated list of the scopes to grant the token. Optional, but a token issued without scopes holds no permissions.
Accepted scopes:
accounts: Allow all permissions for accountsaccounts:readonly: Allow reading accountsaccounts:balances: Allow reading the balance of an accounttransfers: Allow all permissions for bank transfers and reading the bank catalogtransfers:readonly: Allow reading bank transfers and the bank catalogtransfers:prepare: Allow creating bank transfers left pending approvalcards: Allow all permissions for cardscards:readonly: Allow reading cardscards:details: Allow reading the sensitive details of a card: number, security code and expirationspending_controls: Allow all permissions for card spending controlsspending_controls:readonly: Allow reading card spending controlscollection_links: Allow all permissions for collection links and intents, and reading the bank catalogcollection_links:readonly: Allow reading collection links, intents and the bank catalog
More on choosing them in the Scopes section of the authentication guide.
"accounts:readonly transfers"Response Body
application/json
application/json
application/json
curl -X POST "https://api.sandbox.cuentamono.com/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{ "client_id": "your_client_id", "client_secret": "your_client_secret", "grant_type": "client_credentials", "scope": "accounts:readonly transfers" }'{
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"expires_in": 1800,
"refresh_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9refresh...",
"scope": "accounts:readonly transfers",
"token_type": "Bearer"
}{
"error": "unsupported_grant_type",
"error_description": "The grant_type must be 'client_credentials' or 'refresh_token'"
}{
"error": "invalid_client",
"error_description": "Client authentication failed"
}