Mono Colombia

Obtain access token

OAuth 2.0 token endpoint supporting client credentials and refresh token grant types.

Use this endpoint to obtain an access token that can be used to authenticate requests to other API endpoints. The token should be included in the Authorization header as a Bearer token.

Supported Content Types:

  • application/x-www-form-urlencoded (standard OAuth 2.0)
  • application/json

Grant Types:

  • client_credentials: Use client ID and secret to obtain an access token
  • refresh_token: Use a refresh token to obtain a new access token
POST
/v1/oauth/token

Request Body

Token request

TypeScript Definitions

Use the request body type in TypeScript.

client_idstring

Client identifier issued during registration

Example"your_client_id"
client_secretstring

Client secret issued during registration

Example"your_client_secret"
grant_typestring

OAuth 2.0 grant type (must be 'client_credentials')

Value in"client_credentials"
Example"client_credentials"
scope?string

Space-separated list of the scopes to grant the token. Optional, but a token issued without scopes holds no permissions.

Accepted scopes:

  • accounts: Allow all permissions for accounts
  • accounts:readonly: Allow reading accounts
  • accounts:balances: Allow reading the balance of an account
  • transfers: Allow all permissions for bank transfers and reading the bank catalog
  • transfers:readonly: Allow reading bank transfers and the bank catalog
  • transfers:prepare: Allow creating bank transfers left pending approval
  • cards: Allow all permissions for cards
  • cards:readonly: Allow reading cards
  • cards:details: Allow reading the sensitive details of a card: number, security code and expiration
  • spending_controls: Allow all permissions for card spending controls
  • spending_controls:readonly: Allow reading card spending controls
  • collection_links: Allow all permissions for collection links and intents, and reading the bank catalog
  • collection_links:readonly: Allow reading collection links, intents and the bank catalog

More on choosing them in the Scopes section of the authentication guide.

Example"accounts:readonly transfers"

Response Body

application/json

application/json

application/json

curl -X POST "https://api.sandbox.cuentamono.com/v1/oauth/token" \  -H "Content-Type: application/json" \  -d '{    "client_id": "your_client_id",    "client_secret": "your_client_secret",    "grant_type": "client_credentials",    "scope": "accounts:readonly transfers"  }'
{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
  "expires_in": 1800,
  "refresh_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9refresh...",
  "scope": "accounts:readonly transfers",
  "token_type": "Bearer"
}

{
  "error": "unsupported_grant_type",
  "error_description": "The grant_type must be 'client_credentials' or 'refresh_token'"
}

{
  "error": "invalid_client",
  "error_description": "Client authentication failed"
}