OAuth 2.0 using the Client Credentials grant is supported as an alternative authentication method.
This authentication method uses short-lived access tokens rather than sending static credentials with every API request.
OAuth setup must be coordinated during onboarding. Contact Accertify Support or your implementation team if OAuth authentication is required.
OAuth access tokens are requested from the following endpoint:
https://api.accertify.net/api/oauthV1/token
OAuth Authentication Flow
OAuth authentication follows this process:
- Request an access token from the configured OAuth token service.
- Include the access token in the Authorization header of API requests.
- Obtain a new token when the existing token expires.
Example: Authorization: Bearer <access_token>
Requesting an Access Token
OAuth access tokens are obtained using the OAuth 2.0 Client Credentials grant type.
Method 1: Client Credentials in the Request Body
grant_type=client_credentials
client_id=<client_id>
client_secret=<client_secret>
scope=<RTD>
- grant_type must be client_credentials
- scope is the scope assigned to the integration
- client_id is the API user name provided by Accertify
- client_secret is the API secret provided by Accertify
Method 2: Basic Authentication Header
Credentials may also be supplied in the Authorization header.
Authorization: Basic <base64(client_id:client_secret)>
grant_type=client_credentials
scope=<scope>
After obtaining an access token, include it in the Authorization header for API requests:
Authorization: Bearer <access_token>
All subsequent API calls use the bearer token until the token expires or is replaced.
When OAuth 2.0 Is Commonly Used
OAuth 2.0 is commonly selected when:
- Centralized credential management is required.
- Short-lived tokens are preferred over static credentials.
- Organizational security standards require token-based authentication.
- Enterprise integration standards require OAuth-based authentication.
Integration Configuration
Authentication credentials, client identifiers, secrets, tokens, importer identifiers, and related configuration details are issued during onboarding.
Implementation details may vary by environment and integration type. Always use the authentication credentials and endpoints provided for your specific implementation.