Swiftazu

Authentication

Get token

Exchange the client ID and client secret for an access token.

POST/v1/oauth/token
No tokenReturns JSONSuccess 200

This is the only call that needs no token. The token lasts one hour (expires_in is in seconds). Keep it and reuse it; ask for a new one only when it expires. The answer also tells you the Application number and whether it is in demo or live mode.

Request

Headers

FieldTypeDescription
Content-TyperequiredstringAlways application/json when a body is sent.

Request body

FieldTypeDescription
client_idrequiredstringYour Application's client ID. It starts with app_.
client_secretrequiredstringYour Application's client secret. Shown once when the Application was created.
Example request
curl -X POST "https://api.swiftazu.com/v1/oauth/token" \
  -H "Content-Type: application/json" \
  -d '{
  "client_id": "app_f4161f3498e4205e316202cd",
  "client_secret": "YOUR_CLIENT_SECRET"
}'

Response

Example response · 200
{
  "access_token": "at_mfnb3wl_nr80-x8McegJQiEl21MaWK1NM8lx1k3iDOk",
  "token_type": "Bearer",
  "expires_in": 3600,
  "application_id": 100001,
  "mode": "demo"
}

Errors

HTTPCodeMeaning
401invalid_clientThe client ID or the client secret is wrong.
403application_deactivatedThe Application was switched off or suspended.
403secret_expiredThe client secret has passed its expiry date.
403merchant_suspendedYour merchant account is suspended or closed.
403merchant_on_holdYour merchant account is on hold.

Every call can also return the shared errors listed on the Overview page. Overview