Obtain access token
OAuth 2.0 token endpoint supporting client credentials and refresh token grant types.
Use this endpoint to obtain an access token that can be used to authenticate requests to other API endpoints. The token should be included in the Authorization header as a Bearer token.
Supported Content Types:
application/x-www-form-urlencoded(standard OAuth 2.0)application/json
Grant Types:
- client_credentials: Use client ID and secret to obtain an access token
- refresh_token: Use a refresh token to obtain a new access token
Token request
TypeScript Definitions
Use the request body type in TypeScript.
Client identifier issued during registration
"your_client_id"Client secret issued during registration
"your_client_secret"OAuth 2.0 grant type (must be 'client_credentials')
"client_credentials""client_credentials"Space-separated list of the scopes to grant the token. Optional, but a token issued without scopes holds no permissions.
Accepted scopes:
outgoing_transfers: Allow all permissions for outgoing transfersoutgoing_transfers:readonly: Permissions to read outgoing transferstarget_resolutions: Permission to read and resolve target resolutionstarget_resolutions:readonly: Permission to read target resolutionstarget_discoveries: Permission to discover Bre-B keys and read the bank catalogtarget_discoveries:readonly: Permission to read the bank catalogcollections: Allow all permissions for collectionscollections:readonly: Permissions to read collectionstenant_accounts: Allow all permissions for tenant accountstenant_accounts:readonly: Permissions to read tenant accounts
More on choosing them in the Scopes section of the authentication guide.
"outgoing_transfers target_resolutions"Response Body
application/json
application/json
application/json
curl -X POST "https://breb-participant.sandbox.mono.la/api/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{ "client_id": "your_client_id", "client_secret": "your_client_secret", "grant_type": "client_credentials", "scope": "outgoing_transfers target_resolutions" }'{
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"expires_in": 1800,
"refresh_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9refresh...",
"scope": "outgoing_transfers target_resolutions",
"token_type": "Bearer"
}{
"error": "unsupported_grant_type",
"error_description": "The grant_type must be 'client_credentials' or 'refresh_token'"
}{
"error": "invalid_client",
"error_description": "Client authentication failed"
}