Mono Colombia

Obtain access token

OAuth 2.0 token endpoint supporting client credentials and refresh token grant types.

Use this endpoint to obtain an access token that can be used to authenticate requests to other API endpoints. The token should be included in the Authorization header as a Bearer token.

Supported Content Types:

  • application/x-www-form-urlencoded (standard OAuth 2.0)
  • application/json

Grant Types:

  • client_credentials: Use client ID and secret to obtain an access token
  • refresh_token: Use a refresh token to obtain a new access token
POST
/api/v1/oauth/token

Request Body

Token request

TypeScript Definitions

Use the request body type in TypeScript.

client_idstring

Client identifier issued during registration

Example"your_client_id"
client_secretstring

Client secret issued during registration

Example"your_client_secret"
grant_typestring

OAuth 2.0 grant type (must be 'client_credentials')

Value in"client_credentials"
Example"client_credentials"
scope?string

Space-separated list of the scopes to grant the token. Optional, but a token issued without scopes holds no permissions.

Accepted scopes:

  • outgoing_transfers: Allow all permissions for outgoing transfers
  • outgoing_transfers:readonly: Permissions to read outgoing transfers
  • target_resolutions: Permission to read and resolve target resolutions
  • target_resolutions:readonly: Permission to read target resolutions
  • target_discoveries: Permission to discover Bre-B keys and read the bank catalog
  • target_discoveries:readonly: Permission to read the bank catalog
  • collections: Allow all permissions for collections
  • collections:readonly: Permissions to read collections
  • tenant_accounts: Allow all permissions for tenant accounts
  • tenant_accounts:readonly: Permissions to read tenant accounts

More on choosing them in the Scopes section of the authentication guide.

Example"outgoing_transfers target_resolutions"

Response Body

application/json

application/json

application/json

curl -X POST "https://breb-participant.sandbox.mono.la/api/v1/oauth/token" \  -H "Content-Type: application/json" \  -d '{    "client_id": "your_client_id",    "client_secret": "your_client_secret",    "grant_type": "client_credentials",    "scope": "outgoing_transfers target_resolutions"  }'
{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
  "expires_in": 1800,
  "refresh_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9refresh...",
  "scope": "outgoing_transfers target_resolutions",
  "token_type": "Bearer"
}

{
  "error": "unsupported_grant_type",
  "error_description": "The grant_type must be 'client_credentials' or 'refresh_token'"
}

{
  "error": "invalid_client",
  "error_description": "Client authentication failed"
}