Mono Colombia

Obtain access token

OAuth 2.0 token endpoint supporting client credentials and refresh token grant types.

Use this endpoint to obtain an access token that can be used to authenticate requests to other API endpoints. The token should be included in the Authorization header as a Bearer token.

Supported Content Types:

  • application/x-www-form-urlencoded (standard OAuth 2.0)
  • application/json

Grant Types:

  • client_credentials: Use client ID and secret to obtain an access token
  • refresh_token: Use a refresh token to obtain a new access token
POST
/v1/core/oauth/token

Cuerpo de la solicitud

Token request

Definiciones de TypeScript

Usa el tipo request body en TypeScript.

client_idstring

Client identifier issued during registration

Example"your_client_id"
client_secretstring

Client secret issued during registration

Example"your_client_secret"
grant_typestring

OAuth 2.0 grant type (must be 'client_credentials')

Value in"client_credentials"
Example"client_credentials"
scope?string

Space-separated list of the scopes to grant the token. Optional, but a token issued without scopes holds no permissions.

Accepted scopes:

  • ledger: Allow all permissions for ledger resources and reading the programs they run under
  • ledger:readonly: Allow reading ledger resources and the programs they run under
  • payins: Allow all permissions for payins, their templates and their intents, and reading brands and settlement batches
  • payins:readonly: Allow reading payins, their templates, their intents, brands and settlement batches
  • payouts: Allow all permissions for payouts, Bre-B target resolution and the bank catalog
  • payouts:readonly: Allow reading payouts and the bank catalog
  • fx_rates: Allow reading the FX rates of the supported currencies
  • fx_rates:readonly: Allow reading the FX rates of the supported currencies
  • fees: Allow all permissions for fees and the policies that charge them
  • fees:readonly: Allow reading fees and the policies that charge them
  • cards: Allow all permissions for cards
  • cards:readonly: Allow reading cards
  • cards:details: Allow reading the sensitive details of a card: number, security code and expiration
  • spending_controls: Allow all permissions for card spending controls
  • spending_controls:readonly: Allow reading card spending controls

More on choosing them in the Scopes section of the authentication guide.

Example"ledger:readonly payouts"

Cuerpo de la respuesta

application/json

application/json

application/json

curl -X POST "https://api.sandbox.cuentamono.com/v1/core/oauth/token" \  -H "Content-Type: application/json" \  -d '{    "client_id": "your_client_id",    "client_secret": "your_client_secret",    "grant_type": "client_credentials",    "scope": "ledger:readonly payouts"  }'
{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
  "expires_in": 1800,
  "refresh_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9refresh...",
  "scope": "ledger:readonly payouts",
  "token_type": "Bearer"
}

{
  "error": "unsupported_grant_type",
  "error_description": "The grant_type must be 'client_credentials' or 'refresh_token'"
}

{
  "error": "invalid_client",
  "error_description": "Client authentication failed"
}